Lounge of Tomorrow

Lounge of Tomorrow (http://74.208.121.111/LoT/index.php)
-   Egg Head (http://74.208.121.111/LoT/forumdisplay.php?f=13)
-   -   VIRUS warning- critical (http://74.208.121.111/LoT/showthread.php?t=1850)

MickeyLumbo 08-16-2005 02:52 PM

VIRUS warning- critical
 
ZOTOB worm spreading quickly across the nation this hour. seems to be exploiting Windows 2000 95 98 ME and XP.

MickeyLumbo 08-16-2005 02:55 PM

Zotob.A is a worm targeting Windows 2000–based systems which takes advantage of a security issue that was addressed by Microsoft Security Bulletin MS05-039. This worm installs malicious software, and then looks for other computers to infect.

Important If you have installed the update released with Security Bulletin MS05-039, you are already protected from Zotob.A. If you are using any supported version of Windows other than Windows 2000, you are not at risk from Zotob.A.

As part of our Software Security Incident Response Process, our investigation has determined that only a small number of customers have been affected, and Microsoft security professionals are working directly with them. We have seen no indication of widespread impact to the Internet. Customers who believe they have been attacked should contact their local FBI office or post their complaint on the Internet Fraud Complaint Center Web site. Customers outside of the United States should contact the national law enforcement agency in their country.

Check for Infection

When Zotob.A infects a computer, it attempts to deliver a malicious file named Botzor.exe. If your computer is infected, this file will be present and your registry will show changes. Use any of the following methods to check for infection. (If you find the file, you do not need to check the registry, and vice versa.)

Search your computer for the Botzor.exe file

1.

Click Start, point to Search, and then click For Files and Folders.

2.

Click Use Advanced Search Options. Under Search by any or all of the criteria below, enter the following information:

A. Under All or part of the file name: enter Botzor.exe.

B. Under Look in: click Local Hard Drives.

C. Under More Advanced Options, select Search system folders and Search hidden files and folders.

3.

Click Search.

Look for new keys added to the registry

•In registry key HKLM\Software\Microsoft\Windows\
CurrentVersion\Run
added value WINDOWS SYSTEM with data of botzor.exe

•In registry key HKLM\Software\Microsoft\Windows\
CurrentVersion\RunServices
added value WINDOWS SYSTEM with data botzor.exe

If Your Computer Is Not Infected

Help protect your computer against Zotob.A by installing Security Update 899588. Find the download link for your version of Windows in Microsoft Security Bulletin MS05-039.

If Your Computer Is Infected

Follow the Zotob.A recovery steps in the Microsoft Antivirus Encyclopedia.

wendybeth 08-16-2005 09:23 PM

Thanks, Mickey!

Motorboat Cruiser 08-16-2005 09:26 PM

Yeah, thanks for the heads up, ML. :)

MickeyLumbo 08-16-2005 09:29 PM

both WDW and DLR computers were hit today. "the office" was down for several hours this morning. though, i do NOT know if it was related to this virus.

Name 08-16-2005 09:42 PM

In some reports I have read on this virus, worm, if you have XP and have SP2 installed, you have no worries.

Ghoulish Delight 08-16-2005 10:12 PM

Download those Windows updates, folks. Either make sure your automatic updates are running, or head to the Microsoft update site

Kevy Baby 08-16-2005 10:34 PM

Quote:

Originally Posted by Name
In some reports I have read on this virus, worm, if you have XP and have SP2 installed, you have no worries.

You're also okay if you are happily working on a Mac

Not to rub it in or anything

Brigitte 08-17-2005 06:56 AM

Yay for the underdogs ;) My Mac saves me many a worry.

Name 08-17-2005 08:24 AM

My FreeBSD machine is perfectly safe as well... :p

DisneyFan25863 08-17-2005 03:41 PM

Quote:

Originally Posted by Kevy Baby
You're also okay if you are happily working on a Mac

Not to rub it in or anything

Yup...I've been smoothly surfin the net with no antivirus, no spyware protection, and no firewall (except for the one bulit into my router) for over a year with no problems. Gotta love it!

MickeyLumbo 08-17-2005 09:00 PM

this worm (thanks Name) hit both Anaheim and Orlando resorts in a big way!

MickeyLumbo 08-17-2005 10:03 PM

let me add to the above post that only Networked office computers have been affected at the resorts by the worm.

€uroMeinke 08-17-2005 10:17 PM

Quote:

Originally Posted by MickeyLumbo
let me add to the above post that only Networked office computers have been affected at the resorts by the worm.

Ok, so was it you who ate the worm then? Those Disney office parties are getting wilder every year...

Kevy Baby 08-17-2005 10:20 PM

Quote:

Originally Posted by MickeyLumbo
let me add to the above post that only Networked office computers have been affected at the resorts by the worm.

Whew... that takes a load off my mind.

I was deeply concerned that the FastPass® system was down.

€uroMeinke 08-17-2005 10:28 PM

Or the Big Thunder Ride Control system ;)

Kevy Baby 08-17-2005 10:30 PM

Quote:

Originally Posted by €uroMeinke
Or the Big Thunder Ride Control system ;)

No; that was actually hit by the "Red Long John Virus"

MickeyLumbo 08-18-2005 09:31 AM

WKMG: Computer Worm Hits Disney Computers, Locks Reserva
Computer worm briefly locked up reservation systems at Walt Disney World and Disneyland. Also impacted ABC, CNN, The Associated Press, The New York Times and Caterpillar Inc.
Full Story

up and running, but, debugging continues

briefly... more like several hours

Kevy Baby 08-18-2005 10:10 PM

Quote:

Originally Posted by MickeyLumbo
WKMG: Computer Worm Hits Disney Computers, Locks Reserva
Computer worm briefly locked up reservation systems at Walt Disney World and Disneyland. Also impacted ABC, CNN, The Associated Press, The New York Times and Caterpillar Inc.
Full Story

up and running, but, debugging continues

briefly... more like several hours

What's the big idea of staying on topic when we're busy trying to derail it?!?


All times are GMT -7. The time now is 08:36 PM.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.