Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 16 September 2004 18:56:29 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Surila-C copies itself to dx32cxlp.exe in the Windows system and the All Users' startup folder and to systemst.exe to the Windows system folder. The worm also drops other components of itself to dx32cxel.sys and dx32cxconf.ini in the Windows system folder.
In order to autostart itself, W32/Surila-C will set itself up as a service named "dx32cxel" by adding registry entries to:
HKLM\SYSTEM\CurrentControlSet\Services\dx32cxel
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
DisableRegistryTools = 0
W32/Surila-C will prevent access to various security websites by adding entries to the hosts file at:
<Window system folder>\drivers\etc\hosts
