Learn to Remove Net-Worm.Win32.Nimda Step by Step (Virus Removal)

By | September 5, 2014

What do you know about Net-Worm.Win32.Nimda

Net-Worm.Win32.Nimda is a dangerous computer virus which can be classified as a worm. This virus can get into the computer  infected file sharing network, corrupted free programs, malicious links, spam email attachments, malicious secondary storage devices, unauthorized website and so on. Once installed, it will root deeply into the target computer system by injecting its codes to the registry entries and adding file to the system disk. Once the computer starts, it will run at the background automatically.

Once Net-Worm.Win32.Nimda infects target system, it will execute some malicious activities such as change the system files which may lead to system crash. It will slow down the PC performance in somw ways such as slow the loading of the website, windows get stuck,etc. With this vunerability on the computer, other infections can get into the computer easily. It may also record sensitive personal data and send to the cyber criminals. To avoid the further damage, you should remove Net-Worm.Win32.Nimda without delay.

Two effective methods to remove Net-Worm.Win32.Nimda permanently from your computer system

1. Remove Net-Worm.Win32.Nimda manually.

2. Remove Net-Worm.Win32.Nimda by using SpyHunter anti-malware.

Detail instruction:

Method one: Manually remove Net-Worm.Win32.Nimda

B. Follow the steps to continue

Step 1.Disable any suspicious startup items that are made by Net-Worm.Win32.Nimda

Windows Vista or Windows7: click start menu→type msconfig in the search bar → open System Configuration →Disable all possible startup items generated.

Step 2. Show all hidden files and clean all the malicious files.

(1).Click the Start button and choose Control Panel, clicking Appearance and Personalization, to find Folder Options then double-click on it.

(2).In the pop-up dialog box, click the View tab and uncheck Hide protected operating system files (Recommended).

(3). Clean all the malicious files about this infection as below.

%AllUsersProfile%\Application Data\
%AllUsersProfile%\Application Data\random

Step 4. Delete related malicious registry entries .

Open Registry Editor by pressing Window+R keys together.(another way is clicking on the Start button and choosing Run option, then typing into Regedit and pressing Enter. )

registry editor

Delete all the vicious registries as below:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Default_Page_URL" = 
"http://www.<random>.com/?type=hp&ts=<timestamp>&from=tugs&uid=<hard drive id>"


Method two: Automatically get rid of Net-Worm.Win32.Nimda with Spyhunter

SpyHunter is a powerful, real-time anti-spyware application that designed to assist the average computer user in protecting their PC from malicious threats like worms, Trojans, rootkits, rogues, dialers, spyware,etc. To keep SpyHunter Anti-malware on your computer is an important way to protect your computer in a good condition. Please find the instruction as follow.


B. Follow the steps to continue

Step one: Click the icon to download SpyHunter removal tool

download Spyhunter2

Step two: Install Spyhunter.

Open spyh File sph-setup-win7 spyhunter installed

Step three: After the installation, run SpyHunter and click “Malware Scan” button to have a full or quick scan on your PC.


Step four: Select the detected malicious files after your scanning and click “Remove” button to clean up all viruses.

remove all threats

Note: Manually removal is a tough job since there are many related files need to detect and remove. Some files will be hidden so that you cannot find them out and remove completely. If you have been spend much time on manually removal but still cannot fit this problem, you are highly recommended to download Spyhunter antivirus software here to remove Net-Worm.Win32.Nimda and other threats from your system once for all.

<<Download Spyhunter Antivirus to scan your computer for free

Leave a Reply

Your email address will not be published. Required fields are marked *