W32/Agobot-ZY is a network worm which also allows unauthorised remote
access to the computer via IRC channels.
When executed W32/Agobot-ZY moves itself to the Windows system folder
with the filename smssv.exe and sets the registry entries:
HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters
"TrapPollTimeMilliSecs"=dword:<value>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
"Audoi Device Loader"="smssv.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Audoi Device Loader"="smssv.exe"