Sophos

W32/Forbot-FL

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2005 (3.98)
Protection available since 31 August 2005 12:55:10 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\

and remove any reference to any file you deleted.

Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entries:

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\

HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\RunOnce\

and remove any reference to any file you deleted.

Close the registry editor.

More Information

W32/Forbot-FL is a worm and IRC backdoor Trojan for the Windows platform.

W32/Forbot-FL spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).

W32/Forbot-FL runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels. W32/Forbot-FL is a worm and IRC backdoor Trojan for the Windows platform.

W32/Forbot-FL spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).

W32/Forbot-FL runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

When first run W32/Forbot-FL copies itself to <System>\iexplore.exe.

The following registry entries are created to run iexplore.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Intespention
IEXPLORE.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Intespention
IEXPLORE.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Intespention
IEXPLORE.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Intespention
IEXPLORE.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Intespention
IEXPLORE.exe

The file IEXPLORE.exe is registered as a new file system driver service named
"Win32", with a display name of "Intespention". Registry entries are created
under:

HKLM\SYSTEM\CurrentControlSet\Services\Win32\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer