W32/Agobot-ZY

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Several Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Agobot-ZY is a network worm which also allows unauthorised remote
access to the computer via IRC channels.

When executed W32/Agobot-ZY moves itself to the Windows system folder
with the filename smssv.exe and sets the registry entries:

HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters
"TrapPollTimeMilliSecs"=dword:<value>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
"Audoi Device Loader"="smssv.exe"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Audoi Device Loader"="smssv.exe"

download Try Sophos products for free
Download now