Virus Protection > computer-virus-b-page1 > - backdoor.agobot.

backdoor.agobot.

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Backdoor.Agobot.a

Backdoor.Agobot (also known as PhatBot) is a Trojan program which provides the author/ user with remote access to the victim machine. It is managed via IRC. It has a wide range of functionalities:
will not work with a debugger running or under Vmware
it can run both as a standard application and as a service (when running under Windows NT/2000/XP)
when copying itself to the Windows system folder (on first being launched) it attmepts to encode the copy and write the decoder to the body of the copy (polymorphic code)
adds to the HOSTS file the IP address 127.0.0.1 for the sites of some antivirus companies (to hinder the updating of antivirus databases)
monitors the network and copies all interesting packets (e.g. packets containing passwords for FTP servers, e-payment systems such as PayPal etc.)
scans other computers for the presence of common vulnerabilities such as DCOM RPC, UpnP, WebDAV and others, and then installs itself on the vulnerable machine
searches the victim machine for AOL logs, passwords for certain computer games, and email addresses, and sends all this information to its author/ user
conducts DoS attacks (SYN-flood, Targa and others)
launches proxy servers on the victim machine (HTTP, HTTPS, SOCKS, BNC and others)
expedites the uploading of additional modules (plug-ins)

Updated: 02/24/2006
Copyright @2006 backdoor.agobot.
Webroot Software Inc.