
All About Zotob |
|||||||||||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||||||||
How to Remove Zotob.Automated Tools:
Microsoft Manual Zotob Clean: This is an overview of Microsoft's solution 1. Install security update MS05-039 (must use I.E.)
2.
Disconnect from the Internet. 3. End the worm process.
4. Delete the worm files from your computer.
Sources:
Who Create the Zotob?According to MessageLabs, message security company, the Zotob worm was created by Diabl0, possible creator of the Mytob worm.
Sources: News.com.com - Joris Evers Weblog.InfoWold.com - Tom Sullivan
What is Zobot?The worm targets computers running Microsoft Windows 2000 that do not have MS05-039 installed. The Zotob Worm has spread around the world and has brought down systems at CNN, ABC and other networks. It is a decendant of Mytob. Zotob exploits the “plug and play” features of unpatched Win 2000 systems and earlier versions of Windows XP.
The Zotob Worm, like most worms, slows down network connectivity, can shut down/reboot a system, attempts to spread to other systems on the network and ultimately will connect with a remote server to allow downloads of more destructive malware such as virus’ and Trojans. Here are the Zotob Variants:
Sources: http://www.securityfocus.com/news/11283
Why was Zotob Created?``We seem to have a botwar on our hands,'' said Mikko Hypponen, chief research officer at F-Secure. According to Mikko, some later variants actually remove competing malware. What is alarming security professionals is how quickly the worm was implemented after windows announced the systems vulerability. Sources: Virus Writers at War Nytimes.com - Reuters Worm writers dig speed businessweek.com - Arik Hesseldahl
How Serious is the Zotob Worm?F-Secure calls it a Level 2: New virus causing large infections. Might be local to a specific region. Symantec ranks Zotob with a medium damage level but high distrobution rate. Sophos puts Zotob's prevalence level at just below medium. So if the Zotob hardly causes medium damage why is it getting so much attention? Bruce Schneier put it best "..the only reason I can think of that CNN did rolling coverage on it is that CNN was hit by it."
Diabl0 - TurkCoderCreator of Zotob and Mytob Worms Hacked the following sites? IRC = diabl0.turkcoders.ne Finding Diabl0: http://forum.mamboserver.com/showthread.php?t=34303
Great resources on Zotob: Singe.rucus.net Summarizes Zotob History
|
|||||||||||||||||||||||||||||||||||||||||||||