Sophos

W32/Agobot-RN

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 18 April 2005 20:19:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Agobot-RN is a network worm with backdoor functionality for the Windows platform.

The worm allows a remote intruder to gain access and control over the computer via IRC channels. W32/Agobot-RN is a network worm with backdoor functionality for the Windows platform.

The worm allows a remote intruder to gain access and control over the computer via IRC channels.

The worm also modifies the system HOSTS file in order to prevent access to certain websites.

When first run the worm copies itself to ip7.exe in the Windows system folder.

The following registry entries are created to run ip7.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Configuration Loader10
ip7.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Configuration Loader10
ip7.exe

Registry entries are also created under:

HKCR\CLSID\{279816C0-3158-13D1-B2E4-0060975B8649}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer