Results 1 to 10 of 13
-
August 19th, 2005 12:02 PM #1
W32.Zotob.E is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) on TCP port 445.
W32.Zotob.E can run on, but not infect, computers running Windows 95/98/Me/NT4/XP. Although computers running these operating systems cannot be infected, they can still be used to infect vulnerable computers that they can connect to.
Notes:
It has been reported that computers targeted by W32.Zotob.E may become unstable during execution of the exploit code. This may result in the termination of the services.exe process, which causes the targeted computer to shutdown.
Virus definitions version 70816y (extended version 8/16/2005 rev. 25) or greater are required to detect this risk.
Customers running Norton Internet Security 2005 AntiSpyware Edition and Symantec AntiVirus Corporate Edition 10.x can make use of the product's ERASER remediation functionality to remove infections of this risk.
Also Known As: CME-540, Win32.Tpbot.A [Computer Associates], Bozori.A [F-Secure], Net-Worm.Win32.Bozori.a [Kaspersky Lab], W32/Bozori.worm.a!CME-540 [McAfee], W32/Tpbot-A [Sophos], WORM_RBOT.CBQ [Trend Micro]
Type: Worm
Infection Length: 10,366 bytes.
Systems Affected: Windows 2000
-
-
-
August 19th, 2005 12:27 PM #4Originally Posted by marky438
-
-
-
Verified Tsikot Member
- Join Date
- Nov 2002
- Posts
- 66
-
August 19th, 2005 05:32 PM #8
actually this worm can't infect XP if you have all the hotfixes, in our office only a handfull of win2k machines were infected and none of the XPs
-
FrankDrebin GuestAugust 19th, 2005 06:02 PM #9Originally Posted by wrecker
http://securityresponse.symantec.com...2.zotob.e.html
* While computers running Windows 95/98/Me/NT4/XP operating systems cannot be infected remotely, it is possible they could be infected if W32.Zotob.E is executed locally (although this is an unlikely occurrence). Vulnerable Windows 2000 computers could then be infected by the compromised computer.
Also Known As: CME-540, Win32.Tpbot.A [Computer Associates], Bozori.A [F-Secure], Net-Worm.Win32.Bozori.a [Kaspersky Lab], W32/Bozori.worm.a!CME-540 [McAfee], W32/Tpbot-A [Sophos], WORM_RBOT.CBQ [Trend Micro]
Type: Worm
Infection Length: 10,366 bytes.
Systems Affected: Windows 2000
-
Daming issue ng SU7:grin:
Xiaomi E-Car