TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_AGOBOT.BH
Overview

Malware type: Worm

Aliases: Backdoor.Win32.IRCBot.tb (Kaspersky), Exploit-Mydoom (McAfee), W32.Gaobot.SN (Symantec), WORM/SdBot.Gen (Avira), Backdoor:Win32/Sdbot (Microsoft)

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via network shares


Description: 

This worm spreads through network shares. It searches for the following shares, where it drops a copy of itself. It uses a list of user names and passwords to gain access to password-protected shares.

It has backdoor capabilities. It opens a random port, which allows a remote user to perform malicious commands on the affected machine, thus compromising system security.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 21, 2006 1:29:16 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.