Skip to content

Microsoft Security Intelligence

www.microsoft.com September 2, 2026

We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn Microsoft threat actor names

Aliases: No associated aliases

Stop your security software from running

Steal your sensitive information

Download and run other files

Delete security-related files from your PC

Lower your PC security settings

Find out ways that malware can get on your PC .

Use the following free Microsoft software to detect and remove this threat:

Microsoft Defender Antivirus for Windows 10 and Windows 8.1 , or Microsoft Security Essentials for Windows 7 and Windows Vista

Microsoft Safety Scanner

You should also run a full scan. A full scan might find other hidden malware.

This threat tries to steal your sensitive and confidential information. If you think your information has been stolen, see:

What to do if you are a victim of fraud

You should change your passwords after you've removed this threat:

Create strong passwords

You can also visit our advanced troubleshooting page or the Microsoft virus and malware community for more help.

If you’re using Windows XP , see our Windows XP end of support page .

Win32/Sality's main method of installation is by infecting files on the local system. Most variants employ a DLL that is dropped once on each infected machine. The DLL is written to disk in two forms, for example:

\wmdrtc32.dll

\wmdrtc32.dl_

The file with the extension '.dl_' is a compressed copy of the DLL. The DLL contains the bulk of the virus's code.

Sality variants usually attempt to delete files related to anti-virus updates, such as those with the following file extensions:

Stops security-related processes

Win32/Sality commonly searches for and tries to stop security applications, particularly anti-virus and personal firewall programs. It also deletes particular security-related services. Steals sensitive information

Disables User Account Control (UAC) Modifies value: EnableLUA With data: "0" In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System

Modifies Windows Firewall to allow Internet communication by Win32/Sality Adds value: With data: " :*:enabled:ipsec" In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\List

Disables Windows Firewall Modifies value: EnableFirewall With data: "0" In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile

Redirects NETSH event tracing session logging Modifies value: LogSessionName With data: " stdout " In subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh

Turns off monitoring installed Antivirus software within Microsoft Security Center Modifies value: AntiVirusOverride With data: " 1 " In subkeys: HKLM\SOFTWARE\Microsoft\Security Center HKLM\SOFTWARE\Microsoft\Security Center\Svc

Disable Windows Task Manager Modifies value: DisableTaskMgr With data: " 1 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System

Turns "Offline Mode" off in Microsoft Internet Explorer Modifies value: GlobalUserOffline With data: " 0 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings

Allows hidden files to remain hidden Modifies value: Hidden With data: " 2 " In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

Take these steps to help prevent infection on your PC .

The following can indicate that you have this threat on your PC :

You have these files: \wmdrtc32.dll \wmdrtc32.dl_

Infected files may unexpectedly increase in size

Antivirus and firewall applications may fail to function