W32/Virut.A

description-logoAnalysis

  • This virus infects running processes by writing the virus code to the target processes and creating a remote thread to execute it. It avoids infecting the following processes:
    • [system process]
    • system
    • smss.exe
    • csrss.exe

  • Creates a named event to ensure that only one instance of the virus runs on the compromised computer.
  • Connects to the IRC server Proxima.ircgalaxy.pl  using port 65520 on channel &virtu  to await instructions and commands from a malicious user. These commands can cause the infected machine to download malicious files.

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-02-21 91.00794
2023-02-16 91.00640
2023-02-14 91.00573
2023-02-07 91.00363
2023-01-31 91.00154
2023-01-24 90.09944
2023-01-23 90.09917
2023-01-23 90.09916
2023-01-17 90.09734
2023-01-12 90.09587