Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 22 September 2004 13:37:39 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Forbot-AD is a network worm with backdoor Trojan functionality.
W32/Forbot-AD spreads through network shares and by exploiting the LSASS (MS04-011) software vulnerability. The Trojan may also spread through backdoors left open by other malware.
When first run, W32/Forbot-AD copies itself to the Windows System folder as WPSVR.EXE. In order to run automatically each time Windows is started, W32/Forbot-AD sets the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Wireless Provider Server = wpsvr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Wireless Provider Server = wpsvr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Wireless Provider Server = wpsvr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Wireless Provider Server = wpsvr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Wireless Provider Server = wpsvr.exe
W32/Forbot-AD creates a service named "LocalSystem" with the display name "Wireless Provider Server".
The worm runs continuously in the background providing backdoor access to the infected computer through IRC channels.
The backdoor component of W32/Forbot-AD may be used to:
delete network shares.
start a SOCKS4 and SOCKS5 proxy.
start an HTTP and TCP proxy.
list and stop existing processes and services.
download and run files.
modify the registry.
add and delete services.
steal the product keys of popular games and applications.
take part in distributed denial of service (DDOS) attacks.
W32/Forbot-AD is capable of stealing product keys from the following games and applications:
AOL Instant Messenger
Yahoo Pager
.NET Messenger Service
Microsoft Windows Product ID
Counter-Strike
The Gladiators
Gunman Chronicles
Half-Life
Industry Giant 2
Soldiers Of Anarchy
Unreal Tournament 2003
Unreal Tournament 2004
IGI 2: Covert Strike
Freedom Force
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Black and White
Command and Conquer: Generals (Zero Hour)
James Bond 007: Nightfire
Command and Conquer: Generals
Global Operations
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Shogun: Total War: Warlord Edition
FIFA 2002
FIFA 2003
NHL 2002
NHL 2003
Nascar Racing 2002
Nascar Racing 2003
Rainbow Six III RavenShield
Command and Conquer: Tiberian Sun
Command and Conquer: Red Alert 2
Hidden & Dangerous 2
Soldier of Fortune II - Double Helix
Neverwinter Nights
W32/Forbot-AD will attempt to disable other malware, such as members of the W32/Bagle family.
