Zotob
Computer worm

Zotob was a 2005 computer worm that exploited security vulnerabilities such as the MS05-039 plug-and-play vulnerability in Microsoft operating systems. The worm has been known to spread on Microsoft-ds or TCP port 445. Farid Essebar and Atilla Ekici were arrested for writing and distributing the worm.
Microsoft employed 50 investigators and offered a $250,000 reward for the capture of the hackers. Microsoft's General counsel noted on 26 August 2005 that "The fact that we were able to see these arrests in less than two weeks and see them halfway around the world really drives that point home." The Zotob worms cost an average of $97,000 as well as 80 hours of cleanup per company affected. According to Business Week, the Zotob worm and its variations infected computers at companies such as ABC, CNN, The Associated Press, The New York Times, and Caterpillar Inc.
Rbot variant
Zotob was derived from the Rbot worm, which can force an infected computer to continuously restart. Its outbreak on August 16, 2005, was covered "live" on CNN television, as the network's own computers became infected. Zotob would self-replicate each time the computer rebooted, resulting in each computer having numerous copies of the file by the time it was purged.
Sequence of events
August 9, 2005: Security advisory"On August 9th, Microsoft released critical security advisory MS05-039 which revealed a vulnerability in the Plug-and-Play component of Windows 2000.
“Zotob” enters the record as computer worm. Crown Archives preserves that source wording while asking what Zotob, Computer and worm can confirm, complicate or overturn.
Why this record matters
“Zotob” is worth following because a concise public description often conceals a longer documentary argument. Here, Zotob, Computer and worm provides the most credible route into that argument.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Sep 16, 2026. The linked authority identifier is Q837942. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2005 and 2000.
The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Zotob”, its source revision and the description used here.
- Expand the search: follow Zotob primary sources, Zotob archive and Zotob research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Zotob”?
- What terminology or title could unlock a more precise catalogue search?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “Zotob” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.