Sophos

W32/Pushin-A

Aliases
  • Virus.Win32.Diehard.a
  • TrojanDropper:Win32/Cutwail.W
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 22 February 2008 03:18:14 (GMT)
Detected by All Sophos products

Action

More Information

W32/Pushin-A is a virus for the Windows platform.

When first run W32/Pushin-A drops a file in:

<System>\drivers\<random filename>.sys - detected as Troj/Pushu-Gen.

Where <random filename> is in the format: <Capital letter><two lowercase letters><two digits>.

W32/Pushin-A creates the following registry trees to start itself as a driver:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\<random filename>.sys
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\<random filename>.sys
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_<random filename>
HKLM\SYSTEM\CurrentControlSet\Services\<random_filename>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer