Sophos

W32/Scanbot-A

Aliases
  • Backdoor.Agobot.dr
  • IRC-Scanbot
  • Backdoor.IRC.Bot
  • WORM_SCANBOT.A
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from July 2004 (3.83)
Protection available since 26 May 2004 13:57:30 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

Check your administrator passwords and review network security.

More Information

W32/Scanbot-A is a network aware worm with IRC backdoor Trojan functionality.

W32/Scanbot-A copies itself to the folder "drivers" in the Windows system folder using the filename csrss.exe. The worm also drops a DLL to the Windows system folder with the filename csrss.dll. This dll is loaded by the following registry entry when Windows starts up :

HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32\Default = %system%\csrss.dll

The DLL file will execute the main worm executable csrss.exe. On a default Windows installation this registry value contains the value webcheck.dll.

The following registry entries are created but will have no effect:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DumpFaultCheck = %system%

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\DumpFaultCheck = %system%

Where system corresponds to the Windows system folder.

W32/Scanbot-A can be triggered by a remote intruder to scan the internet for computers to infect that have weak administrator passwords.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer