• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

New Forbot variant

SagaLore

Elite Member
Our network was just hit with this. It uses the LSASS exploit. Some of the less used desktops and new machines didn't have their patches, and someone must have brought this in on their laptop.

The reason I'm posting this is although Computer Associates InoculateIT will detect it (after the infection), the Symantec and Sophos removal tools for Forbot/Agobot/Gaobot are not detecting it. InoculateIT cannot remove it.

What is worse, is that a manual removal is proving difficult - it is using tactics I've seen recent spyware use. A combination of the Run/RunOnce registry keys, and a Service that is disabled and "marked for deletion", but still Starts.

The files are "winjsd.exe" called Windows JavaScript Daemon and "wmon32.exe" called WSA Configuration. winjsd.exe is opening up so many ports that it is congesting the network.
 
Back
Top