Sophos

W32/Forbot-FE

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2005 (3.97)
Protection available since 14 July 2005 22:02:05 (GMT)
Detected by All Sophos products

Action

More Information

W32/Forbot-FE is a IRC backdoor Trojan and network worm for the Windows platform.

W32/Forbot-FE connects to a preconfigured IRC server and joins a channel from which an attacker can issue further commands. These commands can cause the infected computer to perform any of the following actions:

flood a remote host (by either ping or HTTP)
start a SOCKS4 proxy server
start an HTTP server
start an FTP server
portscan randomly-chosen IP addresses
execute arbitrary commands
steal information such as passwords and product keys
upload/download files

In order to run automatically when Windows starts up the worm moves itself to the Windows system folder as Messenger.exe and creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Yahoo Updater
Messenger.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Yahoo Updater
Messenger.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Yahoo Updater
Messenger.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Updater
Messenger.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Yahoo Updater
Messenger.exe

W32/Forbot-FE also creates its own service named "Updater", with the display name "Yahoo Updater".

Several registry entries will be created under the following entry:

HKLM\SYSTEM\CurrentControlSet\Services\Updater

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer