Sophos

W32/Doxpar-F

Aliases
  • TROJ_QUKART.U
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 21 January 2006 05:27:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Doxpar-F is a worm for the Windows platform.

W32/Doxpar-F spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including LSASS (MS04-011). W32/Doxpar-F is a worm for the Windows platform.

W32/Doxpar-F spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including LSASS (MS04-011).

When first run W32/Doxpar-F copies itself to <System>\<random filename> and
creates the following files:

\boot.sys
<System>\Cokmgl32.dll

The file boot.sys is detected as Troj/Padodor-Y and the file Cokmgl32.dll is
detected as W32/Doxpar-C.

The following registry entry is created to run code exported by the worm library
on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
DBGA0EEG
(48AC6462-563A-5DB4-6C73-5C2257016F8D)

The file Cokmgl32.dll is registered as a COM object, creating registry entries
under:

HKCR\CLSID\(48AC6462-563A-5DB4-6C73-5C2257016F8D)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer