The Web    Google
11/16: Agobot-NX an IRC Trojan & Worm

11/16: Agobot-NX an IRC Trojan & Worm
November 16, 2004

W32/Agobot-NX is an IRC backdoor Trojan and network worm. W32/Agobot-NX is capable of spreading to computers on the local network protected by weak passwords.

When first run, W32/Agobot-NX copies itself to the Windows system folder as bmsvc32.exe. W32/Agobot-NX runs continuously in the background providing backdoor access to the computer through IRC channels.

W32/Agobot-NX attempts to terminate and disable various anti-virus and security related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loop-back address in an attempt to prevent access to these sites.

More information can be found at Sophos page.

  • Alliance Formed to Finger Hackers
  • Bagle-BK Worm Downloads Code
  • 7/16: Rbot-DP Trojan Has Spreading Capability
  • Bagle-BK Worm Downloads Code
  • Secure Messaging Vendor Offers Management Appliance
  • Feinstein Tightens ID Theft Proposal
  • Gates Sends Letter on Spam to Congress
  • Bagle-AA Moves Maliciously into 3rd Place
  • Palyh and Fizzer Top Troublemakers in May
  • Santy-A Worm Raises Fears Over New Trend
  • Hitachi offers up centralized application security platform
  • Security Camera Articles