Sophos

W32/Surila-C

Aliases
  • Win32.Surila.k
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 16 September 2004 18:56:29 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Surila-C copies itself to dx32cxlp.exe in the Windows system and the All Users' startup folder and to systemst.exe to the Windows system folder. The worm also drops other components of itself to dx32cxel.sys and dx32cxconf.ini in the Windows system folder.

In order to autostart itself, W32/Surila-C will set itself up as a service named "dx32cxel" by adding registry entries to:

HKLM\SYSTEM\CurrentControlSet\Services\dx32cxel

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
DisableRegistryTools = 0

W32/Surila-C will prevent access to various security websites by adding entries to the hosts file at:

<Window system folder>\drivers\etc\hosts

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer