Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | April 2007 (4.16) |
| Protection available since | 22 February 2007 02:56:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for removing W32/Vanebot-AH.
More Information
W32/Vanebot-AH is a worm with backdoor functionality which allows a remote intruder to gain access and control over the computer.
W32/Vanebot-AH spreads to other network computers by scanning network shares for weak passwords and by exploiting common buffer overflow vulnerabilities, including Symantec (SYM06-010).
When first run W32/Vanebot-AH copies itself to <System>\sansv.exe.
The following registry entry is created to run sansv.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SANS Service
System\sansv.exe
