Summary

Summary
Action
More Information
| Included in our products from | June 2004 (3.82) |
|---|---|
| Protection available since | 19 May 2004 11:34:56 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Agobot-IK.
More Information
W32/Agobot-IK is a backdoor trojan.
W32/Agobot-IK allows a malicious user remote access to an infected computer.
In order to run automatically when Windows starts up W32/Agobot-IK creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\
Run\System Service Manager= lsmas.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\System Service Manager=lsmas.exe.
W32/Agobot-IK changes the file C/windows/system32/drivers/etc/hosts
W32/Agobot-IK listens out on ports 1043, 123, 1050, 1046, 1053, 1049 and 1042.
