Threat Database Viruses Virus:Win32/Sality.AT

Virus:Win32/Sality.AT

By Domesticus in Viruses

Virus:Win32/Sality.AT is a malicious computer virus that seems to be legitimate or integrated into legitimate application that waits for users to load and execute it. Virus:Win32/Sality.AT can make changes to the desktop background, enable a criminal to gain unauthorized remote access to the affected computer, infect files and break the PC system, or even leave other nasty malware infections or invade user's privacy. Virus:Win32/Sality.AT is a serious risk for the computer system and needs to be removed immediately.

File System Details

Virus:Win32/Sality.AT may create the following file(s):
# File Name Detections
1. %System%\mmc.exe
2. %System%\cmd.exe
3. %System%\taskmgr.exe
4. c:\gmsv.pif
5. c:\autorun.inf
6. %Windir%\system.ini

Registry Details

Virus:Win32/Sality.AT may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000
HKEY_CURRENT_USER\Software\Apcrmkeh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32

Trending

Most Viewed

Loading...