W32/Bofra.B@mm
| W32/Bofra.B@mm |
Destructivity: |
| • Detected by virus detection files published: 11/9/2004 | • Type: Worm |
| • Virus characteristics first published: 11/9/2004 | • Spreading mechanism: Email, Webpage |
| • Virus characteristics latest update: 2/24/2005 | • Overall risk: Low |
| • Alias: W32/Mydoom.ah@MM, I-Worm/Mydoom.AC, I-Worm.Mydoom.ad, W32.Mydoom.AH@mm, W32/Bofra-B | • Payload: Sets up a webserver and attempts to connect to IRC servers |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
The worm does not come as an attachment. Instead the mails received contain a link to a malformed HTML page residing on another infected system. If the user clicks on this link a buffer overflow exploit will occur in Internet Explorer, causing it to download and execute the worm. When the worm is first run it will copy itself to the Windows System folder, using a random name that always ends with ''32" - f.ex. jaicbw32.exe. It will attempt to copy itself into the memory space of the Windows Explorer process, thus be invisible in the process list. From here it will set up a web server and start its emailing routine. The worm will make a number of changes to the registry: Creates key "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ComExplore\Version". Creates key "HKCU\Software\Microsoft\Windows\CurrentVersion\ Explorer\ComExplore\Version". Deletes value "center" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Deletes value "reactor" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Deletes value "Rhino" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Deletes value "Reactor3" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Deletes value "Reactor4" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Creates value "Reactor5"="C:\WINDOWS\SYSTEM\<WORM FILENAME>" in key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run". Note: The deleted registry entries apparently belongs to previous versions of worms in this series |
||||||||||||||