W32.Zotob.A
Results 1 to 13 of 13

Thread: W32.Zotob.A

  1. #1
    Join Date
    Jan 2003
    Location
    US
    Posts
    5,634

    W32.Zotob.A

    Discovered on: August 14, 2005

    W32.Zotob.A is a worm that spreads using the vulnerability in Microsoft Windows Plug and Play Service (as described in Microsoft Security Bulletin MS05-039). For more details, see the following link.

    http://www.sarc.com/avcenter/venc/data/w32.zotob.a.html
    Eric

  2. #2
    Join Date
    Jul 2004
    Location
    North West England.
    Posts
    9,568
    Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
    27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse

  3. #3
    Join Date
    Apr 2000
    Location
    Friern Barnet, London, England
    Posts
    46,565
    And more here:

    http://www.theregister.co.uk/2005/08/15/zytob_worm/

    This looks like a nasty one. Anyone who hasn't got the latest Windows Updates (especially those running Windows 2000) should get them now.
    Nick.

  4. #4
    Join Date
    Nov 2001
    Location
    Fishbel
    Posts
    2,412
    Quote Originally Posted by SuperSparks
    And more here:

    http://www.theregister.co.uk/2005/08/15/zytob_worm/

    This looks like a nasty one. Anyone who hasn't got the latest Windows Updates (especially those running Windows 2000) should get them now.
    That should go without saying-- however, some people think they or their machines are bulletproof. And when major companies are affected by these things, for which warnings and patches existed at least a week before the outbreak-- that's just sad.
    Welcome to the Eclipse(C). The Evolution of an Idea
    Options: DCM3 LCR VMS CVM Sil CPI VMI ANI 648 CA1 SACD500 Att CID RLS TIME DLG

    Version: ECLIPSE 2.0.0 09/09/98 System is BUSY Thu 07-21-05 1:31 pm
    Access Level = 10 Port = 10

  5. #5
    Join Date
    Oct 2000
    Location
    graham, tx, us
    Posts
    7,156
    The news today is reporting on Zotob.B and varients. MS is downplaying the threat while others say it is more severe.

    Has anyone read that these are back door worms? A couple of reports indicated these worms can take over your computer without you clicking on whatever web page they are embedded in is why I am asking.

    Anyway you look at it though in the end all this evolving malware will cost us little guys more out of our wallets.

    As each MS operating system has come out on the market the size of them get bigger. Maybe we should have an OS the same size and concentrate on the holes more.

    One thing for sure, we have not come close to stopping the bad guys.

  6. #6
    Join Date
    Jul 2004
    Location
    North West England.
    Posts
    9,568
    Worm warning hits highest levels
    McAfee adds IRCbot warning to Zotob landscape...


    Users rushing to protect themselves from the Zotob worm are being warned not to take their eyes off other threats as McAfee raises its alert level on the newly discovered IRCbot to the highest alert.

    The internet relay chat (IRC) worm spreads by exploiting a Microsoft vulnerability. Although a patch has been available since Microsoft announced the vulnerability on 9 August, the spread of the worm suggests users have been slow to apply it.

    The MS05-039 vulnerability has also been leapt on by the virus writers who have launched the recent SDBot family of viruses, Rbot and the Zotob virus which has been causing pain for users around the world in the past 24 hours.

    According to McAfee, the seven day turnaround of the vulnerability being announced and the appearance of the first exploit has been the quickest ever. The IRCbot was the first of the exploits to propagate en masse.

    IRCbot.worm!MS05-039 contacts a remote IRC server and waits for further instructions, according to McAfee. It also copies itself to the Windows System directory, appearing as WINTBP.EXE. Registry keys are created to load the worm at start-up. If the system has not been patched it will continually reboot.

    Liam
    Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
    27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse

  7. #7
    Join Date
    Nov 2000
    Location
    Scotland
    Posts
    320
    I am very glad to have guys at Virtual Doctor around. Although I have automatic updates switched on to advise me of any Win 2000 security updates, I still have not been warned by Microsoft directly about this latest problem. Even when I ask on the MS update page to scan my PC for any critical updates missing, I am still not told about Security Update KB899588. I only found it after reading the VDr posting and a separate email warning from McAfee.

    Any ideas why the MS auto update failed to warn me?

  8. #8
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    May be because Microsoft doesn't consider it "critical"?

    Once you get to the http://windowsupdate.microsoft.com site, instead of clicking the "Express" button, click the "Custom" button and look in the left column for any other "non-critical" updates that may be available for your setup.

  9. #9
    Join Date
    Nov 2000
    Location
    Scotland
    Posts
    320
    I see your point - though McAfee clearly thinks it to be critical.

    On the same topic, though, can you explain the following :

    I have downloaded Security Update KB899588 following VDR and McAfee's advice but it does not show up on the "Review your update history" option on the MS Update Website.

    It does show up within Add / Remove Programs, however.

  10. #10
    Join Date
    Jul 2004
    Location
    North West England.
    Posts
    9,568
    I have downloaded Security Update KB899588 following VDR and McAfee's advice but it does not show up on the "Review your update history" option on the MS Update Website.

    Because it was a manual download and install it appears in Add/Remove, whereas if you had downloaded and installed the update through Windows Update the process would be logged in update history.


    Liam
    Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
    27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse

  11. #11
    Join Date
    Nov 2000
    Location
    Scotland
    Posts
    320
    I now understand. Thanks.

  12. #12
    Join Date
    Jul 2004
    Location
    North West England.
    Posts
    9,568
    No Problem.



    Liam
    Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
    27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse

  13. #13
    Join Date
    Jul 2004
    Location
    North West England.
    Posts
    9,568
    Authorities Nab Zotob Writers

    The FBI arrested two men in connection with this month's computer virus that wreaked havoc on computer networks at companies and government agencies throughout North America.

    During a press conference today, federal officials said Farid Essebar, 18, of Morocco, and Atilla Ekici, 21, of Turkey, were arrested Thursday in their respective countries. They are charged in connection with writing and releasing the Zotob and Mytob worms, according to the FBI.

    Essebar, who used the moniker "Diabl0," and Ekici, known as "Coder," are believed to have worked together on the viruses, although the FBI could not say if they had ever met in person.

    Zotob, a fast moving virus, surfaced earlier this month after Microsoft warned of the security flaw. It hit several media outlets hard, including ABC, CNN, The Associated Press and The New York Times, among others.

    The worm took advantage of the Windows Plug-and-Play vulnerability.

    "This arrest demonstrates the value of public-private collaboration, the first-class investigative work by the authorities and round-the-clock technical and investigative support provided by our Internet Crime Investigations Team here at Microsoft," said Brad Smith, senior vice president and general counsel at Microsoft (Quote, Chart).

    During a joint conference call with FBI officials, Smith said Microsoft's Internet Crime Investigations Team supported the investigation with international law enforcement immediately following the release of the two worms. The company provided technical information and analytical support to the FBI on this case, which was then shared with Moroccan and Turkish authorities.

    Louis M. Reigel III, FBI Cyber Division assistant director, said the worm was in part written by both men.

    Both countries are going to charge the men with crimes, although Reigel could not say which, because of varying laws regulating computer behavior.

    Liam
    Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
    27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •