Home Malware Programs Viruses W32.Sality.Y2!inf

W32.Sality.Y2!inf

Posted: September 27, 2012

Threat Metric

Threat Level: 1/10
Infected PCs: 208
First Seen: September 27, 2012
Last Seen: July 12, 2023
OS(es) Affected: Windows

W32.Sality.Y2!inf is a virus that circulates by corrupting portable executable files on local, removable and remote shared drives. W32.Sality.Y2!inf also deletes certain files from the affected computer. Once executed, W32.Sality.Y2!inf downloads potentially malicious files. W32.Sality.Y2!inf also injects the certain .dll file into all running processes. W32.Sality.Y2!inf may display a message box on the screen of the corrupted machine. W32.Sality.Y2!inf logs keystrokes and then transmits the certain email to remote attackers with an attachment that includes the stolen information. W32.Sality.Y2!inf may also create a peer-to-peer (P2P) botnet and receive URLs of additional files for downloading. W32.Sality.Y2!inf then strives to block security applications.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\oledsp32.dll File name: %System%\oledsp32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Windir%\System.ini File name: %Windir%\System.ini
Mime Type: unknown/ini
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1Title: HLLP.KUKU v3.0a Message: <<<<<Hey, Lamer! Say "Bye-bye" to your data! >>>>> Copywrite (c) by Sector

Loading...