Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 6 June 2005 20:32:14 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Agobot-SW spreads by copying itself to network shares protected by weak passwords.
W32/Agobot-SW runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Agobot-SW copies itself to <Windows system folder>\WinStabilizer.exe and creates the following registry entries to run on startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
WinStabilizer
WinStabilizer.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
WinStabilizer
WinStabilizer.exe
Registry entries are set as follows:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINSTABILIZER\0000
DeviceDesc
WinStabilizer
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINSTABILIZER\0000
Service
WinStabilizer
HKLM\SYSTEM\CurrentControlSet\Services\WinStabilizer
DisplayName
WinStabilizer
W32/Agobot-SW may share/delete the admin$, ipc$, e$, d$, c$ drives. W32/Agobot-SW may attempt to terminate anti-virus and other security-related processes and attempt to prevent access to AV and security related web-sites.
