Slashdot Mirror


Zotob Worm Hits CNN and Goes Global

securitas writes "The Zotob MS05-039 worm mentioned on Slashdot last Sunday may be the most recent virus that has gone global, hitting Windows 2000 desktops at CNN, ABC, the New York Times, and many others. The virus is spreading around the world rapidly as compromised systems become bots and propagate the worm, with reported outbreaks in Germany and China. InformationWeek has a decent article titled Zotob Proves Patching "Window" Non-Existent. Microsoft calls it a "low impact" threat and tells you What you should know about Zotob. Symantec has W32.Zotob.D removal instructions. Trend Micro thinks that this is a new, different worm altogether and says it is one of the fastest-spreading infections in history."

4 of 522 comments (clear)

  1. I wonder... by pointguy · · Score: 5, Interesting

    ... how many computers Apple will sell because of this?

  2. Is it just me... by rootedgimp · · Score: 5, Interesting
    Or does it seem like this new worm proves that there is a digital advertising war going on? Bear with me a second...

    Previously (well, like early-mid 90s) when a site got hacked or a virus was running rampant, there was usually some sort of political message along with it, like a US Gov website getting hacked by a mexican / chinese hacker group that would deface the main index.html to say 'oh these people are doing some bad shit, now we're going to tell you what it is since they wont'
    Notice you don't see that anymore? Like, ever? The new world of commonly noticed 'hackers' seems to be a world of mostly spyware / virus infections targeted at data mining and reselling the information gathered to advertisers. Now, with that in mind, from Symantec's description of what the worm does, look at the following:

    9. Deletes the following registry values:
    "Windows PNP Server" "Windows PNP" "csm Win Updates" "MyWebSearch" "WINDOWS SYSTEM" "Zotob" "MyWay" "WeatherOnTray" "Apropos" "IBIS TB" "TBPS" "Toolbar" "Hotbar" "CMESys" "NavExcel" "ViewMgr" "eZula" "EbatesMoeMoneyMaker" "Ebates" "AutoUpdater" "Gator" "Trickler" "QuickTime" "GatorDownloader" "eZmmod" "Viewpoint" "TkBellExe" "180" "WinTools" "Real" "QuickTime Task" "sais" "msbb" "saie" "180ax" "lgbibsn" "tov"

    from the following subkeys: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Run HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\RunO nce

    10. Searches for the following files and folders to delete the files and the contents of folders:
    * %SYSTEM%\pnpsrv.exe
    * %SYSTEM%\winpnp.exe
    * %SYSTEM%\csm.exe
    * %SYSTEM%\botzor.exe
    * %PROGRAMFILES%\MyWebSearch
    * %PROGRAMFILES%\MyWebSearch\*.exe
    * %PROGRAMFILES%\Hotbar
    * %PROGRAMFILES%\Hotbar\*.exe
    * %PROGRAMFILES%\MyWay
    * %PROGRAMFILES%\MyWay\*.exe
    * %PROGRAMFILES%\180Solutions
    * %PROGRAMFILES%\180Solutions\*.exe
    * %PROGRAMFILES%\Common Files\WinTools
    * %PROGRAMFILES%\Common Files\WinTools\*.exe
    * %PROGRAMFILES%\Toolbar
    * %PROGRAMFILES%\Toolbar\*.exe
    * %PROGRAMFILES%\CxtPls
    * %PROGRAMFILES%\NavExcel
    * %PROGRAMFILES%\AutoUpdate
    * %PROGRAMFILES%\AutoUpdate\AutoUpdate.exe
    * %PROGRAMFILES%\EbatesMoeMoneyMaker
    * %PROGRAMFILES%\eZula
    * %PROGRAMFILES%\eZula\mmod.exe
    * %PROGRAMFILES%\Common Files\GMT
    * %PROGRAMFILES%\Common Files\GMT\GMT.exe
    * %PROGRAMFILES%\CommonFiles\CMEII


    Ever heard of a virus removing spyware for you? What reasons can we think of for a worm to do this? The one that comes to my mind seems far fetched, but assume that the spyware being removed by this virus was engineered by competitors to whoever made this virus. So maybe now we will see turf battles over drone zombified boxen? What other reasons can the /. community present for this virus removing spyware?
  3. SBC by Widowwolf · · Score: 4, Interesting

    Well all i can tell you is SBC is down(thats right the phone company SBC)...company wide!(Cingular is not down at this moment)

    --
    ~~"Of course, that's just my opinion. I could be wrong." ~~Dennis Miller
  4. HAH! Looks like it cleans out spyware! by doormat · · Score: 4, Interesting

    Zotob might be what most people need to clean up their spyware.....

    # Searches for the following files and folders to delete the files and the contents of folders:
      * %SYSTEM%\pnpsrv.exe
      * %SYSTEM%\winpnp.exe
      * %SYSTEM%\csm.exe
      * %SYSTEM%\botzor.exe
      * %PROGRAMFILES%\MyWebSearch
      * %PROGRAMFILES%\MyWebSearch\*.exe
      * %PROGRAMFILES%\Hotbar
      * %PROGRAMFILES%\Hotbar\*.exe
      * %PROGRAMFILES%\MyWay
      * %PROGRAMFILES%\MyWay\*.exe
      * %PROGRAMFILES%\180Solutions
      * %PROGRAMFILES%\180Solutions\*.exe
      * %PROGRAMFILES%\Common Files\WinTools
      * %PROGRAMFILES%\Common Files\WinTools\*.exe
      * %PROGRAMFILES%\Toolbar
      * %PROGRAMFILES%\Toolbar\*.exe
      * %PROGRAMFILES%\CxtPls
      * %PROGRAMFILES%\NavExcel
      * %PROGRAMFILES%\AutoUpdate
      * %PROGRAMFILES%\AutoUpdate\AutoUpdate.exe
      * %PROGRAMFILES%\EbatesMoeMoneyMaker
      * %PROGRAMFILES%\eZula
      * %PROGRAMFILES%\eZula\mmod.exe
      * %PROGRAMFILES%\Common Files\GMT
      * %PROGRAMFILES%\Common Files\GMT\GMT.exe
      * %PROGRAMFILES%\Common Files\CMEII

    --
    The Doormat

    If you're not outraged, then you're not paying attention.