Sophos

W32/Forbot-CB

Aliases
  • Backdoor.Win32.Wootbot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 3 November 2004 13:31:46 (GMT)
Detected by All Sophos products

Action

More Information

W32/Forbot-CB is a network worm which also allows unauthorised remote access to the computer via IRC channels.

W32/Forbot-CB copies itself to the Windows system folder as dialup.exe and entries in the registry at the following locations to run itself on system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Dialup Service

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Windows Dialup Service

HKLM\Software\Microsoft\Windows\CurrentVersion\RunService\
Windows Dialup Service

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Dialup Service

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Windows Dialup Service

HKLM\System\CurrentControlSet\Services\Windows Dialup Service\
ImagePath

W32/Forbot-CB may delete C$, D$, IPC$ and ADMIN$ shares.

The backdoor component of the worm can be used to cause a denial of service by flooding, steal information from predefined registry entries and terminate processes.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer