- Discovered:
- January 21, 2005
- Updated:
- February 13, 2007 12:32:14 PM
- Also Known As:
- Worm.Win32.VB.u [Kaspersky Lab, W32/Nodmin-A [Sophos], WORM_NODMIN.A [Trend Micro]
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
W32.Nodmin@mm is a mass-mailing worm that alters computer settings and spreads via file sharing networks. The worm also attempts to lower security settings by terminating and disabling various anti-virus and security related programs.
This threat is written in Visual Basic.
To manually edit the Hosts file and remove all the entries that the worm added
Note: The location of the Hosts file may vary and some computers may not have this file. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and it is located in the C:\WINNT\system32\drivers\etc folder in Windows 2000. There may also be multiple copies of this file in different locations.
Follow the instructions for your operating system:
- Windows 95/98/Me/NT/2000
- Click Start, point to Find or Search, and then click Files or Folders.
- Make sure that "Look in" is set to (C:) and that "Include subfolders" is checked.
- In the "Named" or "Search for..." box, type:
hosts
- Click Find Now or Search Now.
- For each Hosts file that you find, right-click the file, and then click Open With.
- Deselect the "Always use this program to open this program" check box.
- Scroll through the list of programs and double-click Notepad.
- When the file opens, delete all the entries in Step Number 7 of the "Technical Details" section.
- Close Notepad and save your changes when prompted.
- Windows XP
- Click Start > Search.
- Click All files and folders.
- In the "All or part of the file name" box, type:
hosts
- Verify that "Look in" is set to "Local Hard Drives" or to (C:).
- Click More advanced options.
- Check Search system folders.
- Check Search subfolders.
- Click Search.
- Click Find Now or Search Now.
- For each Hosts file that you find, right-click the file, and then click Open With.
- Deselect the Always use this program to open this program check box.
- Scroll through the list of programs and double-click Notepad.
- When the file opens, delete all the entries in Step Number 7 of the "Technical Details" section.
- Close Notepad and save your changes when prompted.
Antivirus Protection Dates
- Initial Rapid Release version January 21, 2005
- Latest Rapid Release version September 28, 2010 revision 054
- Initial Daily Certified version January 21, 2005
- Latest Daily Certified version September 28, 2010 revision 036
- Initial Weekly Certified release date January 26, 2005
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 0 - 49
- Number of Sites: 0 - 2
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Moderate
Damage
- Damage Level: Medium
Distribution
- Distribution Level: High
Writeup By: Candid Wueest







