Home Malware Programs Worms W32/Sality.gen

W32/Sality.gen

Posted: August 17, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 16
First Seen: January 9, 2011
OS(es) Affected: Windows

W32/Sality.gen is a computer virus that uses known exploits to replicate across vulnerable networks. W32/Sality.gen will set up communication with a remote IRC server and create an executable file in a fake Recycle Bin folder to conceal its presence in the system. W32/Sality.gen contains a keylogger program that can capture all user keystrokes, including confidential details such usernames, passwords and credit card numbers. W32/Sality.gen also has the ability to modify system files by infecting, prepending, or overwriting them. W32/Sality.gen poses a severe threat to PC security and should be terminated immediately.

Aliases

W32/Sality.AF [Panda]Worm/Generic.BCMF [AVG]Win32/Sohaned.worm.230400 [AhnLab-V3]Win32/Yahlover.EV [eTrust-Vet]Packed.Win32.MUPX.Gen [Comodo]W32/AutoRun-YE [Sophos]Win32.WormSohaned.Bp [eSafe]Trojan [K7AntiVirus]I-Worm.Sohanad.gen [CAT-QuickHeal]W32/Sohanat.GQ.worm [Panda]W32/AutoIt.CE!worm [Fortinet]Worm.Win32.AutoIt [Ikarus]Trojan.Win32.AutoIT.gen (v) [Sunbelt]Win32/Autorun.worm.267089 [AhnLab-V3]Worm:Win32/Sohanad.AQ [Microsoft]
More aliases (49)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\gphone.exe File name: gphone.exe
Size: 328.52 KB (328529 bytes)
MD5: 03fa52ab4abe1ce9365615374986c5a9
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: August 13, 2012
%WINDIR%\system32\gphone.exe File name: gphone.exe
Size: 350.2 KB (350208 bytes)
MD5: 6add430404ffe69257a4413ec9d2542a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 9, 2011

Related Posts

Loading...