Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Trend Micro: Windows Worm ZOTOB a Threat

Add as a preferred source on Google

Tokyo-based Internet and security firm Trend Micro reports a new Windows worm, dubbed ZOTOB, has appeared which exploits "critical" security holes in Microsoft’s Windows 95, 98, NT, ME, 2000, and XP operating systems which Microsoft patched just last week. The worm, detected in both the United States and Germany, can block infected users’ access to antivirus sites and give attackers access to infected systems.

So far, Trend Micro reports two variants (ZOTOB A and B) have been discovered. Both take advantage of Microsoft’s Plug and Play technology to propagate across networks; when the worm detects a vulnerable system, it attaches a script to that system which downloads the worm from a clandestine FTP server on the infected machine. Once installed, the worm modifies the system’s HOSTS file to interfere with user’s connecting to specific antivirus Internet sites. The worm also opens a backdoor which enable the computer to receive commands via IRC channels on specific servers; worm variants A and B connect to different IRC servers. Once installed, all data on the infected system is accessible to remote attackers; remote users could also take control of infected systems.

Recommended Videos

To avoid infection by the ZOTOB worms and (undoubtedly) future malware which attempts to exploit the same Windows vulnerabilities, users should make sure their antivirus software is up-to-date and install the latest Microsoft security updates to ensure their systems are not vulnerable to these attacks. The rapid appearance of the ZOTOB worm shortly after Microsoft released system patches emphasizes how critical it can be for Windows users to install security updates promptly and maintain security software. If ZOTOB proves anything, it’s that malware exploiting vulnerabilities in Windows operating systems will appear on the Internet almost instantaneously once the vulnerabilities become widely known outside the computer security industry.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Deepfake bosses are crashing video calls, and researchers are trying to expose them
Seeing your boss on video no longer proves they are real
Researchers at Fraunhofer SIT are fighting against deepfake meeting video calls

Entering into a meeting with your boss and several familiar coworkers inside a video conference is the next area vulnerable to cybercrimes, and it's all because of deepfake technology. Researchers at the Fraunhofer Institute for Secure Information Technology SIT are working on a real-time warning system designed to identify attempted fraud during corporate video conferences.

The report states that criminals are increasingly targeting video meetings for identity theft and financial scams, taking advantage of the trust people place in familiar faces and voices. The intention is to flag suspicious activity while the meeting is still taking place. This gives an employee a chance to stop before following an expensive instruction from an AI-generated executive.

Read more
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more