Sophos

W32/Surila-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Included in our products from November 2004 (3.87)
Protection available since 9 September 2004 21:29:50 (GMT)
Last updated 16 September 2004 09:34:48 (GMT)
Detected by All Sophos products

Action

More Information

W32/Surila-A is a network worm which can copy itself into the StartUp folder and the Windows system folder as DX32CXLP.EXE.

W32/Surila-A can also drop the files DX32CXCONF.INI, DX32CXEL.SYS and SVKP.SYS
into the Windows system folder and overwrite the file named HOSTS in the
C:\<Windows system>\Drivers\etc\ folder with:

127.0.0.1 www.avp.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 www.symantec.com
127.0.0.1 networkassociates.com
127.0.0.1 secure.nai.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 downloads-us1.kaspersky-labs.com
127.0.0.1 downloads-eu1.kaspersky-labs.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.networkassociates.com
127.0.0.1 us.mcafee.com
127.0.0.1 f-secure.com
127.0.0.1 avp.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.kaspersky.com
127.0.0.1 www.f-secure.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 update.symantec.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 viruslist.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 updates.symantec.com
127.0.0.1 kaspersky.com
127.0.0.1 www.trendmicro.com

W32/Surila-A will also create the following registry branches:

HKLM\System\CurrentControlSet\Enum\Root\LEGACY_DX32CXEL\
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_SVKP\
HKLM\System\CurrentControlSet\Services\SVKP\
HKLM\System\CurrentControlSet\Services\dx32cxel\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer