Sophos

W32/Forbot-EC

Aliases
  • Backdoor.Win32.PdPinch.gen
  • WORM_WOOTBOT.GEN
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 15 February 2005 20:56:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Forbot-EC is a network worm with backdoor functionality for the Windows platform. The worm allows unauthorised remote access to the infected system via IRC channels while running in the background as a service process. The worm may also spread by DCC.

W32/Forbot-EC exploits various vulnerabilities, including the LSASS vulnerability (see MS04-011).

The backdoor functionality of the worm includes being able to act as a proxy, sniff packets, download updates, delete network shares and steal keys for various software products. W32/Forbot-EC is a network worm with backdoor functionality for the Windows platform. The worm allows unauthorised remote access to the infected system via IRC channels while running in the background as a service process. The worm may also spread by DCC.

W32/Forbot-EC copies itself to the Windows system folder as EMP32.EXE and creates the following registry entries in order to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Help Temp Files
emp32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Help Temp Files
emp32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Help Temp Files
emp32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Help Temp Files
emp32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Help Temp Files
emp32.exe

W32/Forbot-EC also registers itself as a service named "addicted-to.druggs.info" with the display name "Help Temp Files".

W32/Forbot-EC exploits various vulnerabilities, including the LSASS vulnerability (see MS04-011).

The backdoor functionality of the worm includes being able to act as a proxy, sniff packets, download updates, delete network shares and steal keys for various software products.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer