Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Detecting and Finding Nimda Source

Status
Not open for further replies.

tls9923

Technical User
Aug 7, 2002
155
US
How can I detect and find the source of the Nimda Virus. I show it running on the network but cannot detect where it is running.

Thanks

Terrel
 
You can't. Probably the best way is to use something like Sniffer and capture HTTP traffic. Then you can find out where the source is. I know Sniffer Pro has a Nimda filter.

AVChap
 
I have Sniffer and the Nimda Filter just not sure how to read the results.

Thanks
 
Look at the 3-pane view and check for identical sources of HTTP traffic. You can also use the "eyeball" view to see where the traffic is coming from. You may need to ask your Sniffer guy you help you read the data.

AVChap
 
The source is showing as my unit the one that has sniffer running on it. And for the next 2 weeks I am the Sniffer guy.

Thanks
 
If that's the case, you might be infected :) Try running a full scan (make sure you don't have excluded directories).

AVChap
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top