The 8 Most Common Malware Processes-Scanregw.exe
There are two known
cases of the scanregw.exe process being installed on
computers. One is a genuine and essential process
that belongs to the Windows Operating System while
the other is a malicious application that needs
removing. The malware application uses the same name
as a genuine process in order that you are less
likely to end the active process.
Scanregw.exe, as part of the Windows Operating
System, runs whenever you start your PC. On
execution it will check the registry to determine if
any errors can be found. If errors are found then
they are reported to the user, who is also prompted
to restart Windows at the last known good
configuration. If this process is disabled and the
file removed then an infected computer will not be
subject to this check.
The Stator worm also uses an active process that
goes by the name of scanregw.exe in order to dupe
the user into leaving the process running and the
file in place. The Stator worm propagates via email
and is a mass mailing worm. Once installed on your
computer, the worm will then rename certain programs
and files within your system in order that it can
effectively spread.
