Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 31 August 2005 12:55:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
and remove any reference to any file you deleted.
Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entries:
HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\
HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\RunOnce\
and remove any reference to any file you deleted.
Close the registry editor.
More Information
W32/Forbot-FL is a worm and IRC backdoor Trojan for the Windows platform.
W32/Forbot-FL spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).
W32/Forbot-FL runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.
W32/Forbot-FL is a worm and IRC backdoor Trojan for the Windows platform.
W32/Forbot-FL spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).
W32/Forbot-FL runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.
When first run W32/Forbot-FL copies itself to <System>\iexplore.exe.
The following registry entries are created to run iexplore.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Intespention
IEXPLORE.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Intespention
IEXPLORE.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Intespention
IEXPLORE.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Intespention
IEXPLORE.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Intespention
IEXPLORE.exe
The file IEXPLORE.exe is registered as a new file system driver service named
"Win32", with a display name of "Intespention". Registry entries are created
under:
HKLM\SYSTEM\CurrentControlSet\Services\Win32\
