W32/Stration.DO@mm

Alias/esEmail-Worm.Win32.Warezov.ew, TROJ_STRAT.EQ, W32/Spamta.JC.worm, W32/Strati-Gen, W32/Warezov.EY, W32/Warezov.FJ, Win32.Worm.Stration.BV, Win32/Stration.LZ
Release DateOct 27, 2006
Detection Availability
Active DatabaseExtended Database
FortiGatelowhigh
FortiClient
FortiMailN/A
Current Antivirus Definition Database Version: 11.589
Description

Visible Symptoms

  • Possible firewall alert that an executable is attempting to connect to the internet.
  • System is also infected with W32/Stration.DS@mm.
  • A fake error message box is displayed.

Detailed Analysis

  • Displays the following message box:
    Title: Error
    Message: Unknown error
  • Downloads a file from the following URL, then executes it:
    http://www6.fand[REMOVED]nha.com/chr/831/nt.exe
    This file is detected as W32/Stration.DS@mm.
Description Last Updated Date: Mar 13, 2007
Reference: ID - 299230