Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 21 January 2006 05:27:25 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Doxpar-F is a worm for the Windows platform.
W32/Doxpar-F spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including LSASS (MS04-011).
W32/Doxpar-F is a worm for the Windows platform.
W32/Doxpar-F spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including LSASS (MS04-011).
When first run W32/Doxpar-F copies itself to <System>\<random filename> and
creates the following files:
\boot.sys
<System>\Cokmgl32.dll
The file boot.sys is detected as Troj/Padodor-Y and the file Cokmgl32.dll is
detected as W32/Doxpar-C.
The following registry entry is created to run code exported by the worm library
on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
DBGA0EEG
(48AC6462-563A-5DB4-6C73-5C2257016F8D)
The file Cokmgl32.dll is registered as a COM object, creating registry entries
under:
HKCR\CLSID\(48AC6462-563A-5DB4-6C73-5C2257016F8D)
