| Anti
Virus Scans |
Protection and removal Warning Cryzip Trojan Virus |
Zotob Virus Worm Patchpatch virus zotob Zotob is a Mytob w32 virus that spreads using a vulnerability in Windows Plug and Play service. The worm is a packed PE executable file 22528 bytes long. When run, the Zotob virus worm copies under "SYSTEM" directory using the name botzor.exe and creates a named mutex BOTZOR for making sure that only one copy of the worm is run at the same time. Then it adds the following registry entries to ensure that it is started when a user logs on or the system is restarted: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] The worm also adds the following registry key for diasabling shared access
service: [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess] The worm scans for systems vulnerable to Microsoft Windows Plug and Play service (MS05-039) through TCP/445. It creates 300 threads that connect to random IP addresses within the B-class (255.255.0.0) network of the infected system. First it tests connection to port 445 and if successful, it tries to exploit the vulnerability. If the attack is successful a shell (cmd.exe) is started on port 8888. Through the shell port, the Zotob.exe worm sends a ftp script which instructs the remote computer to download and execute the worm from the attacker computer using FTP. The FTP server listens on port 33333 on all infected computers with the purpose of serving out the worm for other hosts that are being infected. The downloaded file is saved as 'haha.exe' on disk. Here's the summary of the ports used in attack: Port 33333 - FTP server port on infected systems Please
see the following page for detailed information on the vulnerability: The worm
tries to connect to IRC channel at predefined address. The attacker who
knows channel password can instruct the bot to execute
the following
actions: Disconnect/reconnect from the IRC channel Other details |
...Where nothing can possibli go wrong!Remember the 1973 film classic, Westworld? A story about a computer virus 20 years before anyone had heard of 'em. Please watch a little clip from the movie by clicking here.
|
Latest Computer Viruses
|
|
|
|
|||