|W32/Agobot-MP is a network worm and an IRC backdoor Trojan.
It establishes an IRC channel to a remote server to give an unauthorised access to the compromised computer.
It moves itself into the Windows system folder as RUNSVC32.EXE and creates the following registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RunServices = runsvc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\RunServices = runsvc32.exe
It may attempt to terminate anti-virus and other security-related processes, in addition to other viruses, worms or Trojans.
Also, may search for shared folders on a network with weak passwords and copy itself into them.
A text file named HOSTS in C:\ Most of them are antivirus sites.
Please, remove it from startup with antivirus (also check How To Remove section)Startup Optimizer.