W32.Zotob.E is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) on TCP port 445.
W32.Zotob.E can run on, but not infect, computers running Windows 95/98/Me/NT4/XP. Although computers running these operating systems cannot be infected, they can still be used to infect vulnerable computers that they can connect to.
Notes:
It has been reported that computers targeted by W32.Zotob.E may become unstable during execution of the exploit code. This may result in the termination of the services.exe process, which causes the targeted computer to shutdown.
Virus definitions version 70816y (extended version 8/16/2005 rev. 25) or greater are required to detect this risk.
Customers running Norton Internet Security 2005 AntiSpyware Edition and Symantec AntiVirus Corporate Edition 10.x can make use of the product's ERASER remediation functionality to remove infections of this risk.
Also Known As: CME-540, Win32.Tpbot.A [Computer Associates], Bozori.A [F-Secure], Net-Worm.Win32.Bozori.a [Kaspersky Lab], W32/Bozori.worm.a!CME-540 [McAfee], W32/Tpbot-A [Sophos], WORM_RBOT.CBQ [Trend Micro]
Type: Worm
Infection Length: 10,366 bytes.
Systems Affected: Windows 2000


Reply With Quote