Sality.R

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: January 6, 2011
OS(es) Affected: Windows

Sality.R is a harmful virus with file infector functionalities. Sality.R targets executable files with the extensions .exe or .scr, and then it infects them by adding a new code to the host, in which it will insert its malignant code. Sality.R is able to steal a victim's cached passwords and log his/her keystrokes in order to extract sensitive information. Sality.R may also install and execute dangerous payloads that will delete files with certain strings or file extensions. SalityR should be removed immediately after detection as it is also able to disable certain security applications, making a victim's system vulnerable to further attacks.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Ikarus Email-Worm.Win32.Generic
Sunbelt Email-Worm.Win32.Xgtray.gen (v)
AhnLab-V3 Win32/Traxg.worm.53248
BitDefender Win32.Worm.VB.NQU
Kaspersky Email-Worm.Win32.VB.bf
ClamAV Worm.VB-7
CAT-QuickHeal I-Worm.generic.675r
Panda W32/Sality.T
AVG Win32/Sality
Sunbelt Virus.Win32.Sality.r (v)
AhnLab-V3 Win32/Sality.H
Microsoft Virus:Win32/Sality.R
Antiy-AVL Virus/Win32.Sality
eTrust-Vet Win32/Sality.P
AntiVir W32/Sality.Q

SpyHunter Detects & Remove Sality.R

File System Details

Sality.R may create the following file(s):
# File Name MD5 Detections
1. winlogon.exe 37cfaf126f0d89273a004663b7f21e20 2
2. A874F.com 08e03a4c48bfce007dcc2681b34c5e7a 1

Trending

Most Viewed

Loading...