We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Bobax.O
Aliases: Worm:Win32/Bobax.O@mm!CME419 (other) Dropper/Bobax (AhnLab) W32/Netsky.w@MM (Command) Win32.Netsky.W@mm (BitDefender) Win32/Bobax (CA) Win32/Bobax.Z (ESET) Email-Worm.Win32.NetSky.x (Kaspersky) W32/Bobax.worm.gen (McAfee) W32/Bobax.gen1 (Norman) W32/Bobax-S (Sophos) W32.Bobax!dr (Symantec) PE_BOBAX.AH (Trend Micro) I-Worm.Netsky.O (VirusBuster) W32/BOBAX!ITW#16 (Wild List ORG)
Summary
Recovering from recurring infections on a network
-
Ensure that an antivirus product is installed on ALL computers connected to the network that can access or host shares (see above for further detail).
-
Ensure that all available network shares are scanned with an up-to-date antivirus product.
-
Restrict permissions as appropriate for network shares on your network. For more information on simple access control, please see: http://technet.microsoft.com/library/bb456977.aspx.
-
Remove any unnecessary network shares or mapped drives.
Additional remediation instructions for Worm:Win32/Bobax.O
- Stopping and starting Windows services:
- For Windows 7: http://windows.microsoft.com/en-US/windows7/What-are-Administrative-Tools
- For Windows Vista: http://windows.microsoft.com/en-US/windows-vista/What-are-Administrative-Tools
- For Windows XP: http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sys_srv_start_service.mspx
- Enabling Windows Firewall:
- For Windows 7: http://windows.microsoft.com/en-US/windows7/Turn-Windows-Firewall-on-or-off
- For Windows Vista: http://windows.microsoft.com/en-US/windows-vista/Turn-Windows-Firewall-on-or-off
- For Windows XP: http://support.microsoft.com/kb/283673
- Recreating a clean HOSTS file: http://support.microsoft.com/kb/972034
- For other support and help related articles, go to:
- Windows 7: http://support.microsoft.com/gp/windows7
- Windows Vista: http://support.microsoft.com/ph/11732
- Windows XP: http://support.microsoft.com/ph/1173
- Microsoft Security TechNet Center: http://technet.microsoft.com/security/default.aspx