Sophos

W32/Stration-FW

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from July 2007 (4.19)
Protection available since 16 May 2007 04:45:22 (GMT)
Detected by All Sophos products

Action

More Information

W32/Stration-FW is a worm for the Windows platform.

When W32/Stration-FW is installed the following files are created:

<System>\diagisr.dll
<System>\isrprf32.dll
<System>\isrprov.exe

The file diagisr.dll is detected as W32/Strati-Gen.

The following registry entries are created to run W32/Stration-FW on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
himem.exe
<pathname of the worm executable> -s

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SoundMnEx32
<pathname of the worm executable>

The following registry entry is set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<pathname of the worm executable>
<Current Folder>\<original filename>:*:Enabled:SystemVersion

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer