W32/Agobot-ST is a network worm and backdoor Trojan. When started the worm will copy itself to the Windows system folder as service32.exe and sets the following registry entries so as to auto-start on user logon: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ service32 = service32.exe HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ service32 = service32.exe W32/Agobot-ST modifies the HOSTS file in an attempt to redirect or prevent internet traffic to certain addresses. Like other worms from the W32/Agobot family, W32/Agobot-ST will attempt to terminate various security related processes on the host computer in order to avoid detection. Other capabilities include an IRC component, an inbuilt FTP server, ability to scan for network shares with weak passwords, stealing of game passwords and keys found on the host computer, and general backdoor functionality allowing remote access by attackers. More Information  
