This application requires Javascript for optimal performance.

W32/Zotob.D!worm - Released Aug 16, 2005 - Last Updated Oct 05, 2005

Alias/es

Backdoor.Win32.IRCBot.et [KAV], W32.Zotob.D [NAV], W32/Dobgot-A [Sophos], W32/Sdbot.worm!MS05-039 [McAfee], Win32.Zotob.D [CA], WORM_ZOTOB.D [Trend]

Visible Symptoms

  • CVE Reference #: CAN-2005-1983

Detailed Analysis

W32/Zotob.D-net is classified as an Internet worm.  Internet worm has the functionality to spread to other systems using NetBIOS/SMB, SMTP, MSN Messenger, P2P applications, or Mobile network.

The Fortinet Anti-Virus Research Team is currently in the process of creating a detailed description for this virus.

Recommended Action



    FortiGate systems:

  • check the main screen using the web interface to ensure the latest AV/NIDS database has been downloaded and installed -- if required, enable the "Allow Push Update" option


Reference: ID - 71794