ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Free Zotob removal tool offered

Joris Evers CNET News.com

Published: 18 Aug 2005 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Wednesday made available a free software tool to help victims of the worms that hit Windows computers in the past days clean their systems.

The Zotob worm started spreading on Sunday. Since then it along with many of its variants and other worms that take advantage of the same Windows security flaw have hit Windows 2000 users in particular. Systems at CNN, ABC and The New York Times were among those infected.

The cleaning program is an updated version of Microsoft's Windows Malicious Software Removal Tool, Debby Fry Wilson, a director in Microsoft's Security Response Center, said in an interview.

"You click on it and it will tell you if you are infected," she said. "And if you are, it will clean the worm off your PC."

The Windows Malicious Software Removal Tool detects and removes malicious code placed on computers. Microsoft typically releases a new version of the tool every month with its security patches. The tool can be run online through Microsoft's Web site or downloaded from the Microsoft Download Center.

The updated cleaning program checks for and removes infections from Zotob.A through Zotob.E as well as Bobax.O, Esbot.A, Rbot.MA, Rbot.MB and Rbot.MC, according to Microsoft. The list represents all known variants based on Microsoft's investigation, the company said.

"We will continue to investigate reports of future variants and update the tool as necessary based on customer needs," a Microsoft representative said.

Microsoft continues to rate the onslaught of worms as "low to moderate," Fry Wilson said. "The number of customers infected is relatively small," she said. "However, if they are impacted, the pain is certainly real. There is a handful of customers that we have been working with," she said.

The first worm, dubbed Zotob, appeared Sunday and appeared to have faded on Monday. However, several Zotob offshoots and a new worm were subsequently unleashed. New versions of pre-existing threats also began wriggling their way into computers. All exploit a security hole in the plug-and-play feature in Windows. Some experts believe cybercriminals are engaged in a war to infect as many computers as they can.

Microsoft offered a fix for the Windows plug-and-play bug exploited by the worms in its in its monthly patching cycle last week. The software maker deemed the issue "critical", its most serious rating. The first Zotob variant appeared in record time after Microsoft's patch release, giving Windows users little time to fix their systems.

The security issue affects Windows XP and Windows Server 2003, but only PCs running Windows 2000 are susceptible to a remote attack, Microsoft has said.

The worms can infect unpatched Windows 2000 systems that aren't protected by a firewall without any user interaction. The worms typically install a shell program on the computer to download the actual worm code using FTP). The newly infected system then starts searching for new computers to compromise.

Additionally, most of the worms install bot code that lets an attacker remotely control the infected system. Criminals have typically organised these hijacked systems in networks called botnets that are rented out to relay spam, launch extortion scams and other online crimes.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 122 people found this useful


Full Talkback thread

1 comment

  1. Why has MS chosen not to release security patches... Olav Petri

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Fidessa Support Analyst Banking London City

FIDESSA, FIX, ETP, DMA, FIRST LINE SUPPORT, EQUITIES A fantastic opportunity for a Trade Floor Support Analyst with solid Fidessa experience to join ...

Application Support Analyst Equities London City

EQUITIES, FIX, FIDESSA, SQL, JAVA, UNIX, WINDOWS A fantastic opportunity to join one of the investment banks based in the City. Key skills required ...

Applications Support, FIX, Tibco RV, SQL, Wombat, Equities

Applications Support, FIX, Tibco RV, SQL, Wombat, Equities A top Investment Bank requires a candidate with strong experience in Application Support ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment