Hello,
My web server has been attacked by the Nimda virus. I applied the patch but I am already infected.
I think the following system modifications have taken place on my system.
Does anybody know whether there is a cleaner for this problem. Do I have to reinstall my Web Server IIS 4?
I have stopped my web services.
System Modifications
When executed the worm determines from where it is being executed. The worm then overwrites MMC.EXE in the Windows Directory or creates a copy of itself in the Windows Temporary Directory.
The worm then infects commonly used executables listed in the registry keys:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders
The worm hooks the system by modifying the system.ini file as follows:
Shell = explorer.exe load.exe -dontrunold
It also replaces the file Riched20.dll. Riched20.dll is a legitimate Windows .DLL used by applications such as Microsoft Word. By replacing this DLL, the worm is executed each time applications such as Microsoft Word are executed.
The worm copies itself as the file:
%Windows\System%\load.exe