Sophos

W32/Agobot-MX

Aliases
  • Backdoor.Agobot.bh
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 23 September 2004 09:40:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Startup = %SYSTEM%\services21.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Startup = %SYSTEM%\services21.exe

and delete them if they exist.

Close the registry editor.

More Information

W32/Agobot-MX is a network worm with backdoor functionality. When run the worm will attempt to copy itself to the Windows system folder as services21.exe and register itself as a service process.

Sophos Anti-Virus version 3.83 detects this worm as W32/Agobot-Fam without requiring an update. W32/Agobot-MX is a network worm with backdoor functionality. When run the worm will attempt to copy itself to the Windows system folder as services21.exe and register itself as a service process.

The worm will create the following registry entries so as to auto-start on user logon or computer restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Startup = %SYSTEM%\services21.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Startup = %SYSTEM%\services21.exe

W32/Agobot-MX will also attempt to copy itself to the Windows system folder as winhlpp32.exe, tftpd.exe, dllhost.exe, winppr32.exe, mspatch.exe, penis32.exe and msblast.exe. The worm will also attempt to copy itself to network shares, utilizing an inbuilt dictionary to try to guess weak passwords.

The worm will also attempt to connect to an IRC server from where it may receive further commands, scan the local drives for game CD keys, scan the network for vulnerable computers, and terminate various anti-virus and security related processes.

When instructed W32/Agobot-MX can also start a DoS attack, exploit vulnerable computers and act as a proxy or FTP server.

Sophos Anti-Virus version 3.83 detects this worm as W32/Agobot-Fam without requiring an update.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer