Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Nimbda and Klez - odd behaviour with AVD

Thread Tools
 
Search this Thread
 
Old 05 December 2002, 10:05 PM
  #1  
john banks
Scooby Regular
Thread Starter
 
john banks's Avatar
 
Join Date: Nov 2000
Location: 32 cylinders and many cats
Posts: 18,658
Likes: 0
Received 1 Like on 1 Post
Post

Installed AVD on some of our clients today and whilst scanning found the odd Klez and Nimbda, said it could not clean or delete. Tried a removal process as recommended by McAffee and there was nothing there, and the files named were not there (hidden files displayed). Happened with Nimbda on another machine. I know some of these viruses kill parts of the virus killer, but this was up to date engine and pattern files. Seems a bit odd, but systems report as clean even though I never actually managed to delete anything. Seems a bit odd to me?
Old 05 December 2002, 11:08 PM
  #2  
Fig
Scooby Regular
 
Fig's Avatar
 
Join Date: Aug 2002
Location: not forgetting 20,000 posts from last time ;)
Posts: 5,806
Likes: 0
Received 0 Likes on 0 Posts
Post

I had exactly the same thing on my machine last month. Sophos found 300+ files infected with Nimda-A, but no evidence of the hidden files, no modification to any system files etc. Spent several hours running cleanup/disinfectant utilities all reported a clean system.

When I asked Sophos about this, replied that you can get Nimda infection from infected websites just by visiting them. They recommended the on-access scanner part of SAV be set to sweep files on write as well as read, which will detect the files being created should it happen again.

Also check other machines on the LAN because Nimda spreads using network shares
Old 06 December 2002, 12:53 AM
  #3  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

If you get a chance send me a report/log file. I'd like to get them looked at.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
38
17 July 2016 10:43 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
BlkKnight
Non Scooby Related
104
01 October 2015 09:40 PM
Khandaris
ScoobyNet General
11
20 September 2015 12:02 PM



Quick Reply: Nimbda and Klez - odd behaviour with AVD



All times are GMT +1. The time now is 03:10 AM.