Microsoft Security Intelligence
We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn Microsoft threat actor names
Aliases: No associated aliases
Stop your security software from running
Steal your sensitive information
Download and run other files
Delete security-related files from your PC
Lower your PC security settings
Find out ways that malware can get on your PC .
Use the following free Microsoft software to detect and remove this threat:
Microsoft Defender Antivirus for Windows 10 and Windows 8.1 , or Microsoft Security Essentials for Windows 7 and Windows Vista
Microsoft Safety Scanner
You should also run a full scan. A full scan might find other hidden malware.
This threat tries to steal your sensitive and confidential information. If you think your information has been stolen, see:
What to do if you are a victim of fraud
You should change your passwords after you've removed this threat:
Create strong passwords
You can also visit our advanced troubleshooting page or the Microsoft virus and malware community for more help.
If you’re using Windows XP , see our Windows XP end of support page .
Win32/Sality's main method of installation is by infecting files on the local system. Most variants employ a DLL that is dropped once on each infected machine. The DLL is written to disk in two forms, for example:
\wmdrtc32.dll
\wmdrtc32.dl_
The file with the extension '.dl_' is a compressed copy of the DLL. The DLL contains the bulk of the virus's code.
Sality variants usually attempt to delete files related to anti-virus updates, such as those with the following file extensions:
Stops security-related processes
Win32/Sality commonly searches for and tries to stop security applications, particularly anti-virus and personal firewall programs. It also deletes particular security-related services. Steals sensitive information
Disables User Account Control (UAC) Modifies value: EnableLUA With data: "0" In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
Modifies Windows Firewall to allow Internet communication by Win32/Sality Adds value: With data: " :*:enabled:ipsec" In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\List
Disables Windows Firewall Modifies value: EnableFirewall With data: "0" In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
Redirects NETSH event tracing session logging Modifies value: LogSessionName With data: " stdout " In subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh
Turns off monitoring installed Antivirus software within Microsoft Security Center Modifies value: AntiVirusOverride With data: " 1 " In subkeys: HKLM\SOFTWARE\Microsoft\Security Center HKLM\SOFTWARE\Microsoft\Security Center\Svc
Disable Windows Task Manager Modifies value: DisableTaskMgr With data: " 1 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
Turns "Offline Mode" off in Microsoft Internet Explorer Modifies value: GlobalUserOffline With data: " 0 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Allows hidden files to remain hidden Modifies value: Hidden With data: " 2 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Take these steps to help prevent infection on your PC .
The following can indicate that you have this threat on your PC :
You have these files: \wmdrtc32.dll \wmdrtc32.dl_
Infected files may unexpectedly increase in size
Antivirus and firewall applications may fail to function
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
