Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 23 September 2004 09:40:14 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Startup = %SYSTEM%\services21.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Startup = %SYSTEM%\services21.exe
and delete them if they exist.
Close the registry editor.
More Information
W32/Agobot-MX is a network worm with backdoor functionality. When run the worm will attempt to copy itself to the Windows system folder as services21.exe and register itself as a service process.
Sophos Anti-Virus version 3.83 detects this worm as W32/Agobot-Fam without requiring an update. W32/Agobot-MX is a network worm with backdoor functionality. When run the worm will attempt to copy itself to the Windows system folder as services21.exe and register itself as a service process.
The worm will create the following registry entries so as to auto-start on user logon or computer restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Startup = %SYSTEM%\services21.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Startup = %SYSTEM%\services21.exe
W32/Agobot-MX will also attempt to copy itself to the Windows system folder as winhlpp32.exe, tftpd.exe, dllhost.exe, winppr32.exe, mspatch.exe, penis32.exe and msblast.exe. The worm will also attempt to copy itself to network shares, utilizing an inbuilt dictionary to try to guess weak passwords.
The worm will also attempt to connect to an IRC server from where it may receive further commands, scan the local drives for game CD keys, scan the network for vulnerable computers, and terminate various anti-virus and security related processes.
When instructed W32/Agobot-MX can also start a DoS attack, exploit vulnerable computers and act as a proxy or FTP server.
Sophos Anti-Virus version 3.83 detects this worm as W32/Agobot-Fam without requiring an update.
