Sophos

W32/Agobot-HS

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 7 May 2004 14:51:00 (GMT)
Detected by All Sophos products

Action

More Information

W32/Agobot-HS is a member of the W32/Agobot family of worms with a
backdoor component

In order to run automatically when Windows starts up the worm copies itself to the file ns.exe in the Windows system folder and adds the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NS
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\NS.

The worm also registers itself as the service process MSLLR.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer