Sophos

W32/Agobot-IK

Aliases
  • W32.HLLW.Gaobot.gen
  • Backdoor.Agobot.gen
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 19 May 2004 11:34:56 (GMT)
Detected by All Sophos products

Action

More Information

W32/Agobot-IK is a backdoor trojan.

W32/Agobot-IK allows a malicious user remote access to an infected computer.

In order to run automatically when Windows starts up W32/Agobot-IK creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\
Run\System Service Manager= lsmas.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\System Service Manager=lsmas.exe.

W32/Agobot-IK changes the file C/windows/system32/drivers/etc/hosts

W32/Agobot-IK listens out on ports 1043, 123, 1050, 1046, 1053, 1049 and 1042.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer