Modified from Viruscontra
In my previous post (Win32/sality), I've introduced you to win32/sality. Now, I'll tell you some of registry values that may changed by Win32/sality .
Focus your attention on the following notes:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"
- HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
It may also disable settings related to system security. It does this by adding the following registry entries:
- HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\UpdatesDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\UacDisableNotify = dword:00000001
It also disables Registry Editor and Task Manager by adding these registry entries:
- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableTaskMgr = dword:00000001
- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableRegistryTools = dword:00000001
The device driver is not dropped and installed onto the system unless there is an active internet connection.
The virus may prevent execution of applications that perform integrity self-check as a result of them being infected.
So my friend the easiest way to tackle this virus is to Remove above mention Virus Entry Doors from registry and delete those .DLL files from system.
I'll give you the way to do it on my next post...
Bravo blogger Indonesia
Please say thanks to Viruscontra
No comments:
Post a Comment