سلام
اسم اين ويروسW32/Sality.Y
اينارو بخونين
اينارو از توي ارشيو ويروس هاي شناخته شده توسط AVIRA پيدا كردم
Virus: W32/Sality.Y Date discovered: 06/08/2008 Type: File infector In the wild: Yes Reported Infections: Low to medium Distribution Potential: Medium Damage Potential: Medium to high Static file: No IVDF version: 7.00.05.207 Engine version: [ برای مشاهده لینک ، با نام کاربری خود وارد شوید یا ثبت نام کنید ]
General Methods of propagation:
• Local network
• Mapped network drives
Aliases:
• Symantec: W32.Sality.AE
• Mcafee: W32/Sality.gen
• Kaspersky: Virus.Win32.Sality.aa
• TrendMicro: PE_SALITY.JER
• F-Secure: Virus.Win32.Sality.aa
• Sophos: W32/Sality-AM
• Panda: W32/Sality.AK
• VirusBuster: Sality.AQ.Gen
• Bitdefender: Win32.Sality.OG
Platforms / OS:
• Windows 95
• Windows 98
• Windows 98 SE
• Windows NT
• Windows ME
• Windows 2000
• Windows XP
• Windows 2003
Side effects:
• Lowers security settings
• Registry modification
و اينجا :
كار هايي كه اين ويروس ميكنه
File infection Method:
This memory-resistent infector remains active in memory.
70.000
• .EXE
Registry The value of the following registry key is removed:
– [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot]
It creates the following entry in order to bypass the Windows XP firewall:
– [HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplicati ons\List]
• "c:\\%filename%"="c:\\%filename%:*:Enabled:ips ec"
• "c:\windows\\system32\\ctfmon.exe"="c:\windows\\sy stem32\\ctfmon.exe:*:Enabled:ipsec"
The following registry key is added:
– [HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\system]
• "DisableTaskMgr"=dword:00000001
• "DisableRegistryTools"=dword:00000001
The following registry keys are changed:
– [HKLM\SOFTWARE\Microsoft\Security Center]
Old value:
• "AntiVirusDisableNotify"=dword:00000000
• "FirewallDisableNotify"=dword:00000000
• "UpdatesDisableNotify"=dword:00000000
• "AntiVirusOverride"=dword:00000000
• "FirewallOverride"=dword:00000000
New value:
• "AntiVirusDisableNotify"=dword:00000001
• "FirewallDisableNotify"=dword:00000001
• "UpdatesDisableNotify"=dword:00000001
• "AntiVirusOverride"=dword:00000001
• "FirewallOverride"=dword:00000001
• "UacDisableNotify"=dword:00000001
– [HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced]
Old value:
• "Hidden"=dword:00000001
New value:
• "Hidden"=dword:00000002