Page 1 of 1

Has this ever happen to any XP USERS.

Posted: Tue Mar 05, 2002 8:31 am
by fearfox
All the shortcuts on my desktop i have are now for some reason not valid win 32 apps. when i i try to use winamp it says not a valid win32 application. what causes this error. first time i ever seen this error. this is some bs from windows xp

Another things for some exe files it associates it with the stupid Outlook. I was using this computer last night and it was running fine. IF XP acts up i will go back to win2k

Posted: Tue Mar 05, 2002 9:53 am
by dadx2mj
If memery serves me right associating an exe. file with Outlook is a virus. Try running a virus scan and see what it finds.

Posted: Tue Mar 05, 2002 2:58 pm
by Busby
Virus scan is a must!! Sounds like a virus for sure.

Posted: Tue Mar 05, 2002 4:10 pm
by fearfox
fak i got the big one jesus i have been infected shit man. dude check out all file infected.


THIS SYSTEM HAS AN EXTENSIVE VIRUS INFECTION! A PARTIAL LIST OF AFFECTED FILES IS SHOWN BELOW.
The W32/Nimda Virus was found in file D:\cfgwiz32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\cfgwiz.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\main.nws[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\wan.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\bootlog.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\sysdetmg.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\pppndi.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\detlog.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\secur32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\mini.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\secur32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\rpcltc5.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\Programs\comctl32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\Programs\Startup\msprint2.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\Programs\Accessories\hidci.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\ir41_32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\bootlog.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Cookies\drvvfp.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Desktop\voxmsdec.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Favorites\rnasetup.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\NetHood\rpclts5.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\My Documents\rpcltc5.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\PrintHood\rpcltc1.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Recent\issetup.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\SendTo\pci.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Templates\riched20.dll
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Templates\rpclts5.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\intl.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Application Data\nwnds.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\detlog.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\batmeter.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\J8LNPDCD\odbccp32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\L3AIVNZ4\acctres.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\XRX7NXNY\netdi.nws[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Q3R76VOO\frunlog.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\History\advapi32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\History\History.IE5\cfgwiz32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\Default User\Local Settings\Temp\mswsock.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\sysdm.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\msjstick.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\telephon.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\comdlg32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\infrared.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\avicap32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\browselc.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\rpcltc1.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Network\telephon.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\browselc.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\comctl32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\powercfg.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\iphlpapi.nws[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pppndi.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\drvvfp.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\corpol.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\ir41_32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Application Data\MSN6\compobj.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Desktop\avifile.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\ndis2sup.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\acctres.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Startup\msdos.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Accessories\sysdm.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\ndswan16.nws[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\mmsys.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\framebuf.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Accessibility\acelpdec.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\imaadp32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\Games\ccfg95.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\3dfx Tools\msjstick.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\3dfx Tools\Weblinks\cfgwiz.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Start Menu\Programs\SETI@home\rpclts5.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Templates\comdlg32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Favorites\serialui.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Documents\netdtect.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Documents\My Pictures\ipinip.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\ipfltdrv.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Documents\My Music\wsock32.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Documents and Settings\All Users\Documents\My Music\Sample Music\parport.eml[readme.exe]
The W32/Nimda Virus was found in file D:\Docume

Posted: Tue Mar 05, 2002 4:34 pm
by fearfox
this all happen last night cannot believe it. this morning it was like this. good thing is that my server and the other four computers were not infected :D

Posted: Tue Mar 05, 2002 4:41 pm
by Busby
Gotta hate nimda. Luckily it is cleanable. Might wanna consider a reinstall to adjust any settings. We had an outbreak of nimda at a LAN party. We turned off all the switches and made EVERYONE do the nimda detector and cleaner.

Posted: Wed Mar 06, 2002 4:34 am
by ClockerDude
OMG I've seen those .eml files on our network before. Although i'm not sure if its Nimda, i know for a fact that its some sort of Outlook virus, and the files floating are called things like "Brittany Spears nude.eml" and "Nelly furtardo sexy.eml", and the people around here with PCs, (I'm typing this from my iMac) have been trying to get the hell rid of it. I got a couple, and my friends told me to trash them.

Actually, now that my memory has come back online, i remember a mate of mine asked me to go downstairs and tell him what had happened to his comp. Turns out that NAV kept telling him that he had Nimda, and he couldn't get rid of it, so he had to format the drive and reinstall Win98.

Posted: Wed Mar 06, 2002 8:24 am
by DocSilly
http://www.symantec.com/avcenter/venc/d ... .tool.html , this has a removal tool for Nimda.A , there's also a link to a removal tool for Nimda.E ... you might also want to track down the source of the infection if reinfection continues on your network check here for info

Posted: Wed Mar 06, 2002 9:41 am
by bluewhale
ClockerDude: EML files aren' Always Nimda: A client of mine had 4 machines hit by Nimda when it first showed up. It took most of the day to clean them up. Two days later I was at another site and saw an .eml file on someones desktop. Turns out she had been using it for months if not years: no sign of Nimda when scanned.
I don't use OE so can't say for sure but believe it is a normal part of OE. It's just that most people don't have shortcuts going to an EML file on their desktop ;)

Posted: Wed Mar 06, 2002 9:57 am
by fearfox
i got symantec cleaner for nimda yesterday.

thx doc i for link to find out where it came from.