W32/STRAT.EQ!tr - Released Oct 26, 2006
|
Alias/esEmail-Worm.Win32.Warezov.eu, TROJ_STRAT.EQ, W32/Strati-Gen, W32/Warezov.FC, W32/Warezov.gen3!W32DL, Win32.Warezov.DO@mm, Win32/Stration.LZ |
Visible Symptoms
- Possible firewall alert that an executable is attempting to connect to the internet.
- System is also infected with W32/Stration.DS@mm.
- A fake error message box is displayed.
|
Detailed Analysis
- Displays the following message box:
Title: Error
Message: Unknown error
|
- Downloads a file from the following URL, then executes it:
http://www6.fand[REMOVED]nha.com/chr/829/nt.exe
This file is detected as W32/Stration.DS@mm.
|
Recommended Action
FortiGate Systems
- Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
|