Threat Database Viruses W32.Sality!dr

W32.Sality!dr

By GoldSparrow in Viruses

W32.Sality!dr is a computer virus that circulates by corrupting executable files and is known to reduce security settings in order to download other malware programs to your computer system. Once installed, W32.Sality!dr will corrupt local executable files and delete all files that are related to anti-virus and anti-spyware software, as well as firewalls. Once there is the file-sharing network or the network share is not protected, W32.Sality!dr will take advantage of these situations and corrupt the remote computers. W32.Sality!dr circulates ad via email attachments or instant messages.

File System Details

W32.Sality!dr may create the following file(s):
# File Name Detections
1. c:\lroyw.pif
2. c:\autorun.inf

Registry Details

W32.Sality!dr may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32\Security
HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32
HKEY_CURRENT_USER\Software\Apcrmkeh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control

Trending

Most Viewed

Loading...