ɹəuəllıʍ ʇɐb Posted August 17, 2005 Report Share Posted August 17, 2005 Zotob is a worm that targets Windows 2000–based computers and takes advantage of a security issue that was addressed by Microsoft Security Bulletin MS05-039. This worm and its variants install malicious software, and then search for other computers to infect.Details. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted August 17, 2005 Author Report Share Posted August 17, 2005 There are already several variants of the worm, but known under different names (Symantec: W32.Zotob, McAfee: W32/IRCbot.worm!MS05-039, Sophos: W32/Tpbot-A, Trend: WORM_RBOT.CBQ).All Windows 2000 users and up should make sure that all Microsoft security updates are installed, especially 899588. Also make sure that AntiVirus software has the latest virus definitions installed.This is especially important for users that are on a network of computers, as this worm seems to spread directly from computer to computer. Quote Link to comment Share on other sites More sharing options...
Rummy Posted August 17, 2005 Report Share Posted August 17, 2005 Man, What next? Thanks for the info! Quote Link to comment Share on other sites More sharing options...
deuces wild Posted August 17, 2005 Report Share Posted August 17, 2005 http://www.newsnet5.com/technology/4860665/detail.htmlVariations Found In Windows 2000 WormUPDATED: 12:16 pm EDT August 17, 2005SAN FRANCISCO -- A computer security firm in Finland said Wednesday it had detected four new versions of the worm that infected firms such as CNN, the New York Times and Caterpillar. Computers running on Windows 2000 were targeted.Another researcher said there are now 11 variations of the worm, which clogs networks and reboots its host computer.It's difficult to estimate how many computers are affected because the worm travels directly over Internet connections instead of through e-mail attachments.Trend Micro security analyst David Perry said the worms were first known as Rbot.cbq, Sdbot.bzh and Zotob.d.They spread across the Internet Tuesday.Perry said that he considers the attacks to be "small potatoes" in terms of the damage that the worms could inflict. He also anticipates that the threat will be over by Wednesday morning.Download the fix HERE. Quote Link to comment Share on other sites More sharing options...
deuces wild Posted August 17, 2005 Report Share Posted August 17, 2005 Sorry pwillener, did not see your earlier post.Can a mod delete this? It has already been posted.EDIT: I merged them for you :D -- SM Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted August 18, 2005 Author Report Share Posted August 18, 2005 Sorry pwillener, did not see your earlier post.No need to be sorry :) If you haven't seen it, that means that others also may not have seen it. This is something that should be seen by as many as possible, so a duplicate post is better than just one.Anyway, thanks for moving it to this more visible forum. :flowers: Quote Link to comment Share on other sites More sharing options...
andsome Posted August 18, 2005 Report Share Posted August 18, 2005 That's what I like about this forum, everyone looks after everyone else. Quote Link to comment Share on other sites More sharing options...
Thos Posted August 18, 2005 Report Share Posted August 18, 2005 Users of a² should have had a security newsletter yesterday about the Mytob (Zotob) worm and what to do about it. Copy reproduced below: Important information about current security risks. Mytob (Zotob) Worm alert!The latest variants of the Mytob worm use a vulnerability in the Windows Plug&Play interface to infect Windows systems. a-squared detects the worm as Net-Worm.Win32.Mytob.cd, Mytob.cf, Mytob.ch and its automatically installed backdoor trojan as Backdoor.Win32.IRCBot.et. Online newspapers usually use the name Zotob-Worm. The vulnerability mainly affects Windows 2000, but may be used to exploit Windows XP and 2003 Servers too, Microsoft says. Windows 98 and ME systems are not affected.Once active, the worm downloads an IRC backdoor trojan from the internet which is used to remotely control the computer.Protection:Ensure, that you have already applied the Windows patch with the number KB899588 with your system. You can download the patch on the Microsoft website or use the automatic Windows-Update to install it automatically.KB899588: http://www.microsoft.com/technet/security/...n/ms05-039.mspx Windowsupdate: http://www.windowsupdate.coma-squared Free users are advised to run the online update, to be able to remove the worm if the computer becomes infected.a-squared Personal users are protected, even if they don't have the latest online updates installed. The new IDS technology of the background guard immediately detects and blocks the worm with the behavior analysis if it manages to run.Your a-squared Teamhttp://www.emsisoft.comThos. Quote Link to comment Share on other sites More sharing options...
andsome Posted August 18, 2005 Report Share Posted August 18, 2005 Received the newsletter Quote Link to comment Share on other sites More sharing options...
nellie2 Posted August 18, 2005 Report Share Posted August 18, 2005 Symantec have a removal tool that will deal with a few of the zotob variantshttp://securityresponse.symantec.com/avcen...moval.tool.html Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.