Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 3 November 2004 13:31:46 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Forbot-CB.
More Information
W32/Forbot-CB is a network worm which also allows unauthorised remote access to the computer via IRC channels.
W32/Forbot-CB copies itself to the Windows system folder as dialup.exe and entries in the registry at the following locations to run itself on system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Dialup Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Windows Dialup Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunService\
Windows Dialup Service
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Dialup Service
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
Windows Dialup Service
HKLM\System\CurrentControlSet\Services\Windows Dialup Service\
ImagePath
W32/Forbot-CB may delete C$, D$, IPC$ and ADMIN$ shares.
The backdoor component of the worm can be used to cause a denial of service by flooding, steal information from predefined registry entries and terminate processes.
