The Web    Google
12/10: Agobot-NX an IRC Trojan & Worm

12/10: Agobot-NX an IRC Trojan & Worm
December 10, 2004

W32/Agobot-NX is an IRC backdoor Trojan and network worm that is capable of spreading to computers on the local network protected by weak passwords.

When first run, W32/Agobot-NX copies itself to the Windows system folder as bmsvc32.exe. W32/Agobot-NX runs continuously in the background providing backdoor access to the computer through IRC channels.

W32/Agobot-NX attempts to terminate and disable various anti-virus and security related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loopback address in an attempt to prevent access to these sites.

More information can be found at Sophos page.

  • AOL Offers Top 10 Spam List to Aid in Battle
  • 12/8: Rbot-RJ Worm Spreads to Shares
  • 3/7: Kelvir-B an Instant Messaging Worm
  • Humans Still Weakest Security Link
  • 4/7: Rbot-AAF Worm Hits Network Shares
  • Check Point Directing Security to Web Applications, End Points
  • 9/23: Backdoor-CHP Lets Data Through
  • Symantec Beefs Up Security Appliance Line with 5400 Series
  • 11/23: Yanz-B Worm Written in MSVC
  • Fortinet To Deliver 3G Multifunction Security Appliance
  • 3/30: Kelvir-F IM Worm Sends Message
  • Buy Security Camera