W32/Agobot-GN is a member of the W32/Agobot family of worms with
backdoor components for the Windows platform.
The worm allows a malicious user remote access to an infected computer
via IRC.
In order to run automatically when Windows starts up W32/Agobot-GN creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Update Service Process=svrhost23.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Security Update Service Process=svrhost23.exe