Summary

Summary
Action
More Information
| Included in our products from | June 2004 (3.82) |
|---|---|
| Protection available since | 7 May 2004 14:51:00 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please follow the instructions for removing W32/Agobot-HS.
More Information
W32/Agobot-HS is a member of the W32/Agobot family of worms with a
backdoor component
In order to run automatically when Windows starts up the worm copies itself to the file ns.exe in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NS
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\NS.
The worm also registers itself as the service process MSLLR.
