3 hours sleep... hey a body only needs 4 right! 1 to go... The internet is great isn't it? Nimda or Admin spelled backwards... what does it do... hmmm it attacks with a ferocity not seen in any virus before it. Once it's payload has been delivered it attacks 16 known exploits out there. It also tries the land and air approach... you can get it by opening an email, you can get it by opening a web page, hell you can get by sitting there with nothing going on but a web server and before you know it... during the morning yesterday we became infected.
7:45a I notice one of my office mates machines kept trying to load a web page(ours) and this annoying box kept popping up and starting media player with an invalid file...wtf
7:50a I pop up VI and take a look... hmm there seems to be some extra code in the bottom of this page. No sweat remove it save it done...
7:54a Oops that didn't fix it? Let me look ... oh I must not have hit save. There you go done...
7:55a WTF what do you mean it's back already! uh oh!
7:56a Norton AV Center, Mcafee, VirusStalker, Cert hmmm no mention of the symptoms...
8:20a groups.google.com someone is having the same problem and this just now posted!
8:45a Let me walk next door to GoBase2 and see if they are having problems.
8:50a uhhh yea they got it! running wil on thier boxes... ok I'm not alone now. Shut down the site due to possible infection of anyone who looks at it.
9:50a Usenet is starting to have lots of reports of this.
10:20a Symantec has a notice up NEW VIRUS called Nimba!
11:00a Nothing new... this thing replicating everywhere there is a web server. Seems to be adding files at an alarming rate. I just shut down my SQL server and it had 8,000 .EML files on it! Crap! This thing looks like a mass mailer I hope I didn't bomb out 8,000 people!
11:30a Ok getting a handle on it... run M$ patch to stop the vulnerability from CodeBlue(3 weeks old now) delete 78K *.eml and *.nws files ... this seems to have stopped it one machine but 3 others are spinning out of control still.
12:15p Damn I'm hungry... still at it.
12:30p Several places are reporting the virus now including CNN and NewsMax. At least one of my servers has the words "USa Goverment Sucks" embedded in evey web page... thank god I don't use that server for weeb stuff!
2:00p Starting to look like an all nighter... One step forward one step back...
3:30p I seem to have a handle on the 2 most important servers, I had to just shut one of the other off and pull the plug.
5:00p ok Our web site is back up and running Virii free for the moment.