Sophos

W32/Bobax-A

Aliases
  • TrojanProxy.Win32.Bobax.a
  • W32/Bobax.worm.a
  • Win32/Bobax.A
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 18 May 2004 15:40:29 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Bobax-A is a network worm with backdoor functionality.

W32/Bobax-A drops a randomly named dll to the temp folder which contains
all the main functionality of the worm.

The executable component will be copied to the Windows system folder with a
random file name and creates a randomly named value in the following registry
entries so that the worm is run when a user logs on to Windows:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

The DLL is loaded into the explorer process and will initially send a request
to a hacker on a machine at one of the following domains:

dns4biz.org
hopto.org
no-ip.info

W32/Bobax-A will create a backdoor to the compromised computer and an
attacker will be able to use that backdoor to instruct the worm to begin scanning
random IP addresses for machines that the worm can copy itself to using the
LSASS vulnerability. This vulnerability is reportedly fixed in Microsoft Security Bulletin MS04-011.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer