Sophos

W32/Agobot-VB

Aliases
  • Backdoor.Agobot.gen
  • W32/Gaobot.worm.gen.j
  • W32.Gaobot.AFJ
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 30 April 2004 16:13:36 (GMT)
Detected by All Sophos products

Action

More Information

W32/Agobot-VB is a backdoor Trojan and worm which spreads to computers
protected by weak passwords.

When first run, W32/Agobot-VB copies itself to the Windows system folder as
uu.exe and creates the following registry entries to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\yx=uu.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\yx=uu.exe

The Trojan runs continuously in the background providing backdoor access to
the computer.

The Trojan attempts to terminate and disable various anti-virus and security
related programs and modifies the HOSTS file located at
%WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus
websites to the loopback address 127.0.0.1 in an attempt to prevent access to these sites.

W32/Agobot-VB queries the following websites to test internet connectivity:

www.microsoft.com
www.level3.com
www.nifty.com
www.akamai.com
www.ryan1918.org
www.ryan1918.net
www.google.com
de.yahoo.com
www.xo.net
www.lib.nthu.edu.tw
www.belwue.de
e.yotta-byte.net

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer