The Web    Google
12/10: Agobot-NX an IRC Trojan & Worm

12/10: Agobot-NX an IRC Trojan & Worm
December 10, 2004

W32/Agobot-NX is an IRC backdoor Trojan and network worm that is capable of spreading to computers on the local network protected by weak passwords.

When first run, W32/Agobot-NX copies itself to the Windows system folder as bmsvc32.exe. W32/Agobot-NX runs continuously in the background providing backdoor access to the computer through IRC channels.

W32/Agobot-NX attempts to terminate and disable various anti-virus and security related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loopback address in an attempt to prevent access to these sites.

More information can be found at Sophos page.

  • 4/13: Spybot-NLX Worm Has DDoS Abilities
  • 9/30: Trojan.Duckey Exploits JPEG Flaw
  • 1/18: Zar Worm Sends Tsunami Email
  • Understanding and Preventing DDoS Attacks
  • 2/21: MyDoom-BC an Email Worm for Windows
  • 3/9: Forbot-AB Worm Uses Network Shares
  • 2/8: Wallz Worm Exploits LSAS Flaw
  • Will Sobig Strike Again?
  • E-mail security and your legal liability
  • 5/11: Rbot-ACH Worm Spreads Via Shares
  • InstaGate SCM Offers Integrated Secure Content Management
  • Security Camera Companies and products