The Web    Google
11/16: Agobot-NX an IRC Trojan & Worm

11/16: Agobot-NX an IRC Trojan & Worm
November 16, 2004

W32/Agobot-NX is an IRC backdoor Trojan and network worm. W32/Agobot-NX is capable of spreading to computers on the local network protected by weak passwords.

When first run, W32/Agobot-NX copies itself to the Windows system folder as bmsvc32.exe. W32/Agobot-NX runs continuously in the background providing backdoor access to the computer through IRC channels.

W32/Agobot-NX attempts to terminate and disable various anti-virus and security related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loop-back address in an attempt to prevent access to these sites.

More information can be found at Sophos page.

  • 10/29: Beagle@mm!CPL Detects Worms
  • Check Point Adds Application Protection To Firewall
  • Should You Hack Your Own Network?
  • 10/21: Bloodhound.Exploit-17 Detects Files
  • 4/15: Kelvir-J an IM Worm
  • 1/10: VBS/Mcon-G Worm Spreads Via IRC
  • 11/11: Masteq-H Trojan Runs Silently
  • Virus Alert: Optix.Pro Trojan Rated Low Threat
  • 10/28: Agobot-NU a Worm and Backdoor
  • Group Revises Anti-Piracy License Terms
  • Virus Alert: Optix.Pro Trojan Rated Low Threat
  • Security Camera Product