Sophos

W32/Forbot-BQ

Aliases
  • Backdoor.Win32.Wootbot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Included in our products from December 2004 (3.88)
Protection available since 20 October 2004 09:30:44 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\

and remove any reference to any file you deleted.

Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entries:

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\RunOnce\

and remove any reference to any file you deleted.

Close the registry editor.

More Information

W32/Forbot-BQ is a network worm with backdoor Trojan functionality.

The worm runs continuously in the background providing backdoor access to the infected computer.

W32/Forbot-BQ spreads through network shares and by exploiting the LSASS (MS04-011) software vulnerability. The worm may also spread through backdoors left open by other malware. W32/Forbot-BQ is a network worm with backdoor Trojan functionality.

W32/Forbot-BQ spreads through network shares and by exploiting the LSASS (MS04-011) software vulnerability. The worm may also spread through backdoors left open by other malware.

When first run, W32/Forbot-BQ copies itself to the Windows System folder as WIN32USB.EXE. In order to run automatically each time Windows is started, W32/Forbot-BQ sets the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
USB Device = win32usb.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
USB Device = win32usb.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
USB Device = win32usb.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
USB Device = win32usb.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
USB Device = win32usb.exe

W32/Forbot-BQ creates a service named "blargh" with
the display name of "USB Device".

The worm runs continuously in the background providing backdoor access to the infected computer through IRC channels.

The backdoor component of W32/Forbot-BQ can be used to:

start an FTP and HTTP server.
delete network shares.
start a SOCKS4, SOCKS5, HTTP, TCP and GRE proxy.
list and stop existing processes and services.
upload, download, run and delete files.
modify the registry.
add and delete services.
steal the product keys of popular games and applications.
scan other computers for open ports and attempt to exploit them.
take part in distributed denial of service (DDOS) attacks.
flush the DNS cache.
logoff, reboot and shut down the computer.

W32/Forbot-BQ may delete the ADMIN$, IPC$, C$ and D$ network shares.

W32/Forbot-BQ is capable of stealing product keys from the following games and applications:

Unreal Tournament 2003
Unreal Tournament 2004
The Gladiators
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
Shogun: Total War: Warlord Edition
Rainbow Six III RavenShield
Neverwinter Nights
Need For Speed Hot Pursuit 2
Need For Speed: Underground
NHL 2002
NHL 2003
Nascar Racing 2002
Nascar Racing 2003
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
James Bond 007: Nightfire
Industry Giant 2
IGI 2: Covert Strike
Hidden & Dangerous 2
Half-Life
Gunman Chronicles
Global Operations
Freedom Force
FIFA 2002
FIFA 2003
Counter-Strike
Command and Conquer: Tiberian Sun
Command and Conquer: Red Alert 2
Command and Conquer: Generals (Zero Hour)
Command and Conquer: Generals
Black and White
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Yahoo Pager
AOL Instant Messenger
Call of Duty
Microsoft Messenger Service
Microsoft Windows Product ID

W32/Forbot-BQ may alter the following registry entry in order to enable/disable DCOM:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM

W32/Forbot-BQ will attempt to disable other malware, such as members of the W32/Bagle family.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer