ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Zotob worm makes little progress

Joris Evers CNET News.com

Published: 16 Aug 2005 09:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new worm that was unleashed over the weekend affects only a limited group of Windows users and has not wreaked any widespread havoc, according to Trend Micro.

As of Monday morning on the West Coast of the US, the original Zotob.A had infected about 50 computers worldwide, and the first variant, Zotob.B, had compromised about 1,000 systems, the antivirus software maker said.

"There are not that many infections," said David Perry, director of global education at Trend Micro.

The worm, which has spawned at least two variants, exploits a hole in the plug-and-play feature in the Windows operating system. It surfaced only days after Microsoft offered a fix for the "critical" bug as part of its monthly patching cycle.

While early reports on Zotob suggested it was spreading rapidly, the impact of the worm has actually been restricted because it targets PCs running Windows 2000, an older version of the software, Microsoft said. It poses no threat to computers running Windows XP and Windows Server 2003, the company added.

"Only a small number of customers have actually been affected," said Stephen Toulouse, a program manager in Microsoft's security group. "It is not something that has any type of widespread impact on the Internet... It hits Windows 2000 customers very specifically."

Zotob appeared in record time after Microsoft's patch release, according to Trend Micro. "This is the fastest turnaround from the announcement of the vulnerability to an actual virus," Perry said.

Last Tuesday, Microsoft issued patches to fix the plug-and-play vulnerability in various versions of Windows. The bulletins included fixes for Windows XP and Windows Server 2003, even though the software maker already said at the time that only PCs running Windows 2000 were susceptible to a remote attack via the vulnerability.

While more recent editions of Windows are available, but Windows 2000 remains popular. The operating system ran on 48 percent of business PCs during the first quarter of 2005, according to a recent study by AssetMetrix.

Users of Windows 2000 should be on guard, especially if they are not using a firewall, said Mikko Hyppönen, director of antivirus research at software maker F-Secure. Zotob.A and Zotob.B scan the Internet for vulnerable systems using TCP port 445, a port typically blocked by a firewall, he said.

When a target system is found by Zotob, it installs a shell program on the computer that downloads the actual worm code, named Haha.exe, using FTP. The newly infected system then starts searching for new computers to compromise.

A second offshoot, Zotob.C, adds a mass-mailing capability, which means it can also spread by email.

The worm itself doesn't have a destructive payload, but the first two versions do let the attacker commandeer the infected machine. "It leaves an open back door. It could download anything," Perry said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 121 people found this useful


Full Talkback thread

2 comments

  1. uhuh Anonymous
  2. Remember: it's a "Microsoft worm", not a "computer... Olav Petri

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

2nd Line Support / Field Support Engineer

You will need to maintain software licences and hardware databases, and also re-image PCs. My client based in South Yorkshire, urgently requires 6 ...

Firewalls Engineer Lead

Ensure all firewall related break/fix SLA timescales are met and all associated reporting is completed in a full and timely fashion. Activities and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment