• Virus is 32 bit with a file size of 22,331 bytes
  • If virus is run, it will copy itself into the undefinedWindowsundefined\System32 folder as "updt32v4.exe"
  • The virus will also modify the registry to auto run at Windows startup -

    "Configuration update" = UPDT32V4.EXE [extra data]

    "Configuration update" = UPDT32V4.EXE [extra data]

  • The virus will attempt to connect to the Internet IP address using TCP port 6001, and await instructions from a hacker or group of hackers

Recommended Action

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option