W32Bobax
W32/Bobax is a mass-mailing worm that spreads through email and infects Windows system. W32/Bobax spreads with a random filename and carries a spoofed 'From' address picked up randomly from the infected system. Upon execution of the infected attachment, W32/Bobax copies itself in a random name with an .exe extension under the Windows System folder. To propagate itself, W32/Bobax gathers email addresses from the Windows Address Book and Windows Messenger Contact list of the infected system. W32/Bobax mails an infected file detected as W32/Small.AXR to these addresses using its own SMTP engine.
Comments Off