Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 29 August 2006 13:55:00 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Womble-A is a mass mailing worm for the Windows platform.
W32/Womble-A uses Exp/WMF-A which exploits a vulnerability in the image rendering functionality of the DLL GDI32.DLL, which allows the execution of arbitrary code (MS06-001).
It may arrive as an email with the following subject line:
!!
Action
Action
Beauty
Bush
FIFA
Helo
Hi
important
Incredible!!
info
Laura
Laura and John
Lola
Look at this!!!
Miss Khan
Nataly
Ola
Olympus
Paula
pic
private
private pics
Re:
Re: pic
read this
Robert
Sex
The email may have a message body of:
Attach File...
The attachments may have the following filenames:
free_antivirus.pif.zip
mails.jpg
some_info.wmf
www.jpg.zip
your_friends.wmf.zip
When run, the Worm copies itself to <System>\<Original Filename of Worm>.exe
The following registry entries are set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ms_net_update
<System>\<Original Filename of Worm>.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ms_net_update
<System>\<Original Filename of Worm>.exe
