Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | March 2005 (3.91) |
| Protection available since | 3 February 2005 09:14:28 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random character name> = <path to worm>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
<random character name> = <path to worm>
and remove any reference to any file you deleted.
Close the registry editor.
More Information
W32/Bobax-H is a mass-mailing Sasser-like worm that uses the MS04-011(LSASS.exe) vulnerability to propagate.
W32/Bobax-H also carries an email relay module which may allow the infected computer to be used for transmission of unsolicited emails. W32/Bobax-H is a mass-mailing Sasser-like worm that uses the MS04-011 (LSASS.exe) vulnerability to propagate.
When run W32/Bobax-H creates a helper dll in the temp folder with a random name. When the dll is loaded the executable component moves itself to the Windows system folder using a random name.
W32/Bobax-H sets the following registry entry in order to auto-start on computer reboot:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random character name> = <path to worm>
On computers running the Windows 9x Operating System the following registry entry will also be created:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
<random character name> = <path to worm>
W32/Bobax-H also carries an email relay module which may allow the infected computer to be used for transmission of unsolicited emails.
W32/Bobax-H may modify the HOSTS file so as to deny access to various anti-virus and security websites.
The worm will harvest email addresses from files found on the infected computer with the extensions of HTM, TXT and DBX.
Emails generated by the worm have the following characteristics:
Message text chosen from:
Saddam Hussein - Attempted Escape, Shot dead
Attached some pics that i found
Osama Bin Laden Captured.
Attached some pics that i found
Testing
Secret!
Hey,
Remember this?
Hello,
Long time! Check this out!
Hey,
I was going through my album, and look what I found..
Hey,
Check this out :-)
Attachment name chosen from the following list with randomly
chosen extension of (PIF, SCR, EXE, ZIP):
Cool
pics.1
funny.1
bush.1
joke.1
secret.2
