| Anti
Virus Scans |
Protection and removal Warning Cryzip Trojan Virus |
Botzor.exe Patch VirusBotzor.exe is an internet worm, using the Windows bug MS05-039 Plug and Play Buffer Overflow to penetrate the computer. This worm doesn’t spread by email. The Botzor.exe worm creates 300 threads that connect to random IP addresses. First it tests connection to port 445 and if successful, it tries to exploit the vulnerability. If the attack is successful, a shell (cmd.exe) is started on port 8888. Through the shell port, the worm sends a ftp script which instructs the remote computer to download and execute the worm from the attacker computer using FTP. The
file named "botzor.exe" is created in the system folder (one
of C:\Windows\System, C:\Windows\System32, C:\WinNT\System32 depending
on the Windows version) on an infected computer. Few registry keys are modified.
The
worm is activated by the registry item "WINDOWS SYSTEM" with
the value "botzor.exe" in the keys: The Win32:Zotob-D uses the name "windrg32.exe". Botzor.exe worm file is saved to the subfolder "wbev" of the system folder, for example C:\Windows\System32\Wbev\windrg32.exe. It connects to few IRC servers. The worm tries to end processes with the names "botzor.exe", "cmesys.exe", "csm.exe", "cxtpls.exe", "ebatesmoemoneymaker.exe", "nhupdater.exe", "pnpsrv.exe", "qttask.exe", "realsched.exe", "viewmgr.exe", "winpnp.exe". It adds item named "WinDrg32" with the value "%system%\wbev\windrg32.exe" to the key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. It deletes items of few different adwares and older versions of Zotob from this key and the key HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\RunOnce. It also deletes files and folders of those adwares. Win32:Zotob-E uses filename "wintbp.exe". The item in the HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run key is named "wintbp". Zotob.exe is a Mytob clone that spreads using a vulnerability in Windows Plug and Play service (MS05-039). |
...Where nothing can possibli go wrong!Remember the 1973 film classic, Westworld? A story about a computer virus 20 years before anyone had heard of 'em. Please watch a little clip from the movie by clicking here.
|
Latest Computer Viruses
|
|
|
|
|||