Avira Virus Lab

W32/Sality.L

  • Name
    W32/Sality.L
  • Date discovered
    Oct 8, 2015
  • Type
    Malware
  • Impact
    High 
  • Reported Infections
    Low 
  • Operating System
    Windows
  • VDF version
    6.35.00.108 (2006-06-29 11:57)

Stay safe from all these threats with Avira Free Antivirus.

Avira Free Antivirus Download Free

The term 'W32' denotes a virus that runs on 32-bit Windows systems and infects files.

  • VDF
    6.35.00.108 (2006-06-29 11:57)
  • Aliases
    Avast: Win32:Sality-AB
    AVG: Win32/Sality
    ClamAV: W32.Sality.N
    Dr. Web: Win32.Sector.20480
    F-PROT: W32/Sality.K (exact)
    Trend Micro: PE_SALITY.AE
    Microsoft: Virus:Win32/Sality.G
    G Data: Win32.Sality.E
    Kaspersky Lab: Virus.Win32.Sality.l
    Bitdefender: Win32.Sality.E
    ESET: Win32/Sality.NAE virus
  • Files
    The following files are deleted:
    • %SYSDIR%\wmimgr32.dl_
    • %DISKDRIVE%\KUKU300a
    The following files are created:
    • %SYSDIR%\wmimgr32.dl_
    • %SYSDIR%\wmimgr32.dll
    • %USERPROFILE%\Local Settings\Application Data\Microsoft\Media Player\wmdbexport.xml
    • %DISKDRIVE%\KUKU300a
    The following files are changed:
    • %USERPROFILE%\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb
    • %WINDIR%\system.ini
    • %PROGRAM FILES%\Common Files\Java\Java Update\jusched.exe
    • %DISKDRIVE%\67edd601553864307ce739a3c57414fe\DeleteTemp.exe
    • %DISKDRIVE%\67edd601553864307ce739a3c57414fe\DW20.EXE
    • %DISKDRIVE%\67edd601553864307ce739a3c57414fe\setup.exe
  • Injections
    • %SYSDIR%\cmd.exe
    • %SYSDIR%\ipconfig.exe
    • %DISKDRIVE%\hips\loader.exe
    • %WINDIR%\System32\svchost.exe
    • %FILE_PATH%
    • {<-%SYSDIR%\wmimgr32.dll}
    • \SystemRoot\System32\smss.exe{<-%SYSDIR%\wmimgr32.dll}
    • \??\%SYSDIR%\csrss.exe{<-%SYSDIR%\wmimgr32.dll}
    • \??\%SYSDIR%\winlogon.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\services.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\lsass.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\VMware\VMware Tools\vmacthlp.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\svchost.exe{<-%SYSDIR%\wmimgr32.dll}
    • %WINDIR%\System32\svchost.exe{<-%SYSDIR%\wmimgr32.dll}
    • %WINDIR%\Explorer.EXE{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\spoolsv.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\FileZilla Server\FileZilla Server Interface.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\VMware\VMware Tools\VMwareTray.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\VMware\VMware Tools\vmtoolsd.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\FileZilla Server\FileZilla Server.exe{<-%SYSDIR%\wmimgr32.dll}
    • %WINDIR%\System32\alg.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\wscntfy.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\Java\jre7\bin\jqs.exe{<-%SYSDIR%\wmimgr32.dll}
    • %DISKDRIVE%\totalcmd\TOTALCMD.EXE{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\wbem\wmiprvse.exe{<-%SYSDIR%\wmimgr32.dll}
    • %PROGRAM FILES%\WinPcap\rpcapd.exe{<-%SYSDIR%\wmimgr32.dll}
    • %DISKDRIVE%\hips\vhsnz.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\cmd.exe{<-%SYSDIR%\wmimgr32.dll}
    • %SYSDIR%\ipconfig.exe{<-%SYSDIR%\wmimgr32.dll}
    • %DISKDRIVE%\hips\loader.exe{<-%SYSDIR%\wmimgr32.dll}
    • %FILE_PATH%{<-%SYSDIR%\wmimgr32.dll}
  • Registry
    The following registry entries are changed:
    • HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences ("LegacyContentProviderName": ""; "MigrationSchema": "{97D9A710-B59F-43E5-86AC-26C21F8B12D3}"; "MigrationPercentage": dword:00000064; "MigratedXML": dword:00000000)

Help make the web safer by sending us suspicious files/URLs to analyze

Submit your file/URL or Go to Avira Answers

Why submit a suspicious file?

If you encountered a suspicious file or website that’s not in our database, we’ll analyze it and determine whether it’s harmful. Our findings are then pushed out to our millions of users with their next virus database update. If you have Avira, you’ll get that update too. Don’t have Avira? Get it on our homepage.

What’s Avira Answers?

It’s our thriving community of technical professionals and part-time experts, working together to help solve tech problems. It’s the perfect place to pose your question to a community of fellow Avira users.