Nimda
malicious file infecting computer worm

The Nimda virus is a malicious file-infecting computer worm.
The first released advisory about this threat (worm) was released on September 18, 2001.
Nimda affected both user workstations (clients) running Windows 95, 98, NT, 2000, or XP and servers running Windows NT and 2000.
The worm's name comes from the reversed spelling of "admin".
F-Secure found the text "Concept Virus(CV) V.5, Copyright(C)2001 R.P.China" in the Nimda code, suggesting its country of origin. However, they also noted that a computer in Canada was responsible for an October 11, 2001 release of infected emails alleging to be from Mikko Hyppönen and Data Fellows (F-Secure's previous name).
Methods of infection
Nimda proved effective partially because it—unlike other infamous malware like Code Red—uses five different infections vectors:
Open network shares
Browsing of compromised web sites
Exploitation of various Internet Information Services (IIS) 4.0 / 5.0 directory traversal vulnerabilities. (Both Code Red and Nimda were hugely successful in exploiting well-known and long-solved vulnerabilities in the Microsoft IIS Server.)
Back doors left behind by the "Code Red II" and "sadmind/IIS" worms.
The public source identifies “Nimda” as malicious file infecting computer worm. This brief keeps that definition visible, then builds a research path around Nimda, malicious and file.
Why this record matters
A short description can identify a subject without explaining its stakes. For “Nimda”, the useful work is to connect “malicious file infecting computer worm” to the records capable of establishing context and consequence.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Mar 27, 2026. The linked authority identifier is Q1048338. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2001 and 2000.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Nimda”, its source revision and the description used here.
- Expand the search: follow Nimda primary sources, Nimda archive and Nimda research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Nimda”?
- Which cited source is closest to the event, object or claim?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “Nimda” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.