Skip to main content
Published Apr 23, 2008 | Updated Sep 15, 2017

Trojan:JS/Nimda.A

Detected by Microsoft Defender Antivirus

Aliases: HTML/Nimda (AhnLab) JS/Nimda.A@mm (Command) I-Worm/Nimda.A.HTM (AVG) JS.Nimda.A (BitDefender) JScript/Chir.B.Worm (CA) Win32/Chir.B (ESET) Net-Worm.Win32.Nimda (Kaspersky) W32/Nimda.htm (McAfee) HTML/Nimda.A@mm (Norman) W32/Chir-B (Sophos) W32.Chir.B@mm(html) (Symantec) JS_NIMDA.A (Trend Micro) JS.Chir.B (VirusBuster)

Summary

Trojan:JS/Nimda.A is a trojan that attempts to open the malicious file “readme.eml” in the current folder. The file “readme.eml” is a malformed multipart MIME formatted message file dropped by Worm:Win32/Nimda, and it contains an encoded copy of Worm:Win32/Nimda.
 
Trojan:JS/Nimda.A takes advantage of a vulnerability corrected by MS01-020 (Incorrect MIME Header Can Cause IE to Execute E-mail Attachment).
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us