Threat Database Viruses W32/Sality.gen.z

W32/Sality.gen.z

By GoldSparrow in Viruses

W32/Sality.gen.z is a computer virus that seems to be a legitimate program, but, in fact, is a malicious threat. W32/Sality.gen.z may proliferate by infecting files on a network file system or a file system that is shared by another computer. W32/Sality.gen.z may be installed for malicious purposes by a hacker enabling to get remote access to the infected computer in order to steal passwords, Internet banking and personal information. W32/Sality.gen.z changes system security center, registry entries and disables anti-virus software and firewall. You need to remove W32/Sality.gen.z as soon as possible.

SpyHunter Detects & Remove W32/Sality.gen.z

File System Details

W32/Sality.gen.z may create the following file(s):
# File Name MD5 Detections
1. C:\System\[RANDOM CHARACTERS]
2. C:\autorun.inf
3. C:\Documents and Settings\\Application Data\[RANDOM CHARACTERS]
4. C:\Program Files\[RANDOM CHARACTERS]
5. C:\WINDOWS\system32\Drivers\[RANDOM CHARACTERS]
6. C:\Documents and Settings\\Local Settings\Temp\[clear all]
7. C:\[RANDOM CHARACTERS]
8. C:\WINDOWS\system32\[RANDOM CHARACTERS]
9. C:\Documents and Settings\\Local Settings\Temporary Internet Files\[clear all]
10. file.exe b3f6c2aeb149d574f1964561dfdde834 0
11. file.exe 63426bd39d187987a8174e942f98c4b5 0
12. file.exe 6d5ddca7e24be34c64b463c6fce8265e 0
13. file.exe f541c117a8a1ff9bee9d8257d93523ca 0
14. file.exe 766578a9f04e02cd4d192928b60b3b7f 0

Registry Details

W32/Sality.gen.z may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Trending

Most Viewed

Loading...