
ZOTOB.E
WORM SPREADS IN THE WILD
Virus Name : W32.Zotob.E
Alias : WORM_RBOT.CBQ,
I-Worm/Generic, IRCBOT.Worm
Virus type : Internet
worm
Threat
level : Medium
Virus
details :
Zotob.E aka Rbot.cbq is a
network Worm, exploits LSASS and Microsoft
Windows Plug and Play Service (PNP)
vulnerabilities present in Windows as explained
by Microsoft Security Bulletin MS04-011 and
MS05-039.
When the worm file is
executed, copies itself to Windows System folder
as Wintbp.exe in the background.
Zotob modifies registry run section to load
automatically on the next startup. The registry
modification is given below.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
"Wintbp" = "Wintbp.exe"
Zotob worm generates
random IP addresses, and it will try to infect
vulnerable computers. This worm appeared on 16th
August 2005.
Microsoft has released
the patch for the MS04-011 and MS05-039
vulnerabilities. They can be downloaded from the
following links:
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
http://www.microsoft.com/technet/security/bulletin/ms05-039.mspx
How can I protect my
system?
Solo has incorporated
W32.Zotob.E aka WORM_RBOT.CBQ in its signature
file to protect users from this worm attack. Make
sure that you have installed registered version
of Solo Antivirus to protect your system from all
virus threats.
How
to remove this worm?
Solo
antivirus can detect and remove W32.Zotob.E aka
WORM_RBOT.CBQ
and its variants safely. Use the
following link to Download 30 day trial
version of Solo antivirus
to
remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VB, Java scripts,
Trojans, Backdoors, boot sector, partition table
and macro viruses.
You can
purchase Solo antivirus using the link 

|