W32/Agobot-HI is a member of the W32/Agobot family of worms with a backdoor
component.
In order to run automatically when Windows starts up the worm copies itself to
the file csrss32.exe in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
System Update Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
System Update Service.
The worm also modifies the file \windows\system32\drivers\etc\hosts to disable name resolution to anti-virus websites.