W32/Agobot-HS is a member of the W32/Agobot family of worms with a
backdoor component
In order to run automatically when Windows starts up the worm copies itself to the file ns.exe in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NS
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\NS.
The worm also registers itself as the service process MSLLR.