Gammiy

By Sumo3000 in Viruses

Gammiy is a malicious computer virus which searches network shares for executable files as well as infects all such files it detects. Gammiy sets network shares by joining to hosts with pointless IP addresses. Gammiy additionally downloads an additional infection, customarily the backdoor, as well as personally installs it to the affected PC system. Gammiy runs upon each Windows start-up, as well as each time the user opens the content document. Remove Gammiy from your machine immediately after you detect it.

File System Details

Gammiy may create the following file(s):
# File Name Detections
1. smss.exe
2. dntboot.bin
3. dbst32nt.log

Registry Details

Gammiy may create the following registry entry or registry entries:
HKEY_CLASS_ROOTtxtfileShellOpenCommand(Default)=%System%dbst32nt.log notepad.exe %1
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonUserinit=%System%userinit.exe,%Windows%smss.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell=explorer.exe %Windows%smss.exe

Trending

Most Viewed

Loading...