Sophos

W32/Bobax-H

Aliases
  • Email-Worm.Win32.Bobic.a
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Included in our products from March 2005 (3.91)
Protection available since 3 February 2005 09:14:28 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random character name> = <path to worm>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
<random character name> = <path to worm>

and remove any reference to any file you deleted.

Close the registry editor.

More Information

W32/Bobax-H is a mass-mailing Sasser-like worm that uses the MS04-011(LSASS.exe) vulnerability to propagate.

W32/Bobax-H also carries an email relay module which may allow the infected computer to be used for transmission of unsolicited emails. W32/Bobax-H is a mass-mailing Sasser-like worm that uses the MS04-011 (LSASS.exe) vulnerability to propagate.

When run W32/Bobax-H creates a helper dll in the temp folder with a random name. When the dll is loaded the executable component moves itself to the Windows system folder using a random name.

W32/Bobax-H sets the following registry entry in order to auto-start on computer reboot:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random character name> = <path to worm>

On computers running the Windows 9x Operating System the following registry entry will also be created:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
<random character name> = <path to worm>

W32/Bobax-H also carries an email relay module which may allow the infected computer to be used for transmission of unsolicited emails.

W32/Bobax-H may modify the HOSTS file so as to deny access to various anti-virus and security websites.

The worm will harvest email addresses from files found on the infected computer with the extensions of HTM, TXT and DBX.

Emails generated by the worm have the following characteristics:

Message text chosen from:

Saddam Hussein - Attempted Escape, Shot dead
Attached some pics that i found

Osama Bin Laden Captured.
Attached some pics that i found

Testing
Secret!

Hey,
Remember this?

Hello,
Long time! Check this out!

Hey,
I was going through my album, and look what I found..

Hey,
Check this out :-)

Attachment name chosen from the following list with randomly
chosen extension of (PIF, SCR, EXE, ZIP):

Cool
pics.1
funny.1
bush.1
joke.1
secret.2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer