Summary

Summary
Action
More Information
| Protection available since | 26 May 2004 13:57:30 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Check your administrator passwords and review network security.
More Information
W32/Scanbot-A is a network aware worm with IRC backdoor Trojan functionality.
W32/Scanbot-A copies itself to the folder "drivers" in the Windows system folder using the filename csrss.exe. The worm also drops a DLL to the Windows system folder with the filename csrss.dll. This dll is loaded by the following registry entry when Windows starts up :
HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32\Default = %system%\csrss.dll
The DLL file will execute the main worm executable csrss.exe. On a default Windows installation this registry value contains the value webcheck.dll.
The following registry entries are created but will have no effect:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DumpFaultCheck = %system%
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\DumpFaultCheck = %system%
Where system corresponds to the Windows system folder.
W32/Scanbot-A can be triggered by a remote intruder to scan the internet for computers to infect that have weak administrator passwords.
