W32/Agobot-ME is an IRC backdoor Trojan and network worm.
W32/Agobot-ME is capable of spreading to computers on the local network protected by weak passwords.
When first run W32/Agobot-ME moves itself to the Windows system folder as mssvc32.exe and creates the following registry entries to run itself on system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
mssvc32 = mssvc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
mssvc32 = mssvc32.exe
On NT-based versions of Windows the worm creates a new service named "mssvc32" with the startup property set to automatic, so that the service starts automatically each time Windows is started.
Each time W32/Agobot-ME is run it attempts to connect to a remote IRC server and join a specific channel. The worm then runs continuously in the background, allowing a remote intruder to access and control the computer via IRC channels.
W32/Agobot-ME attempts to terminate and disable various anti-virus and security related programs.
W32/Agobot-ME attempts to restrict access to several anti-virus and security related websites by appending the following to the HOSTS file:
127.0.0.1
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.