Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 22 February 2008 03:18:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
More Information
W32/Pushin-A is a virus for the Windows platform.
When first run W32/Pushin-A drops a file in:
<System>\drivers\<random filename>.sys - detected as Troj/Pushu-Gen.
Where <random filename> is in the format: <Capital letter><two lowercase letters><two digits>.
W32/Pushin-A creates the following registry trees to start itself as a driver:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\<random filename>.sys
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\<random filename>.sys
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_<random filename>
HKLM\SYSTEM\CurrentControlSet\Services\<random_filename>
