Summary

Summary
Action
More Information
| Protection available since | 18 May 2004 15:40:29 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Bobax-A is a network worm with backdoor functionality.
W32/Bobax-A drops a randomly named dll to the temp folder which contains
all the main functionality of the worm.
The executable component will be copied to the Windows system folder with a
random file name and creates a randomly named value in the following registry
entries so that the worm is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
The DLL is loaded into the explorer process and will initially send a request
to a hacker on a machine at one of the following domains:
dns4biz.org
hopto.org
no-ip.info
W32/Bobax-A will create a backdoor to the compromised computer and an
attacker will be able to use that backdoor to instruct the worm to begin scanning
random IP addresses for machines that the worm can copy itself to using the
LSASS vulnerability. This vulnerability is reportedly fixed in Microsoft Security Bulletin MS04-011.
