Alias: Backdoor.Agobot.3.gen (Kaspersky),
MS03-026 Exploit.Trojan,
W32/Gaobot.worm.gen (McAgee)
Category: Win32
Type: Worm
Published Date: 11/30/2003
Last Modified: 12/1/2003
CHARACTERISTICS
Win32.Agobot.BN is an IRC controlled backdoor that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares or by utilizing the DCOM RPC vulnerability (MS03-039) when instruced to. It will only run on NT-based operating systems.
More information and patches to address this vulnerability can be found at Microsoft here: http://www.microsoft.com/technet/security/bulletin/MS03-026.asp
It appears to also exploit Webservers running IIS using the WebDav exploit (MS03-007). Please visit Microsoft for more information on this vulnerability http://www.microsoft.com/technet/security/bulletin/MS03-007.asp .
http://www3.ca.com/virusinfo/virus.aspx?ID=37670

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic