Skip to main content
Microsoft Security Intelligence
Published Sep 10, 2008 | Updated Sep 15, 2017


Detected by Microsoft Defender Antivirus

Aliases: W32.Spybot.Worm (Symantec) TROJ_AGENT.EAG (Trend Micro)


Worm:Win32/Slenfbot.CZ is a worm that can spread via MSN Messenger, and may spread via removable drives. The worm also contains backdoor functionality that allows unauthorized access to an affected machine. This worm does not spread automatically upon installation, but must be ordered to spread by a remote attacker.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner ( For more information, see
Follow us