Mass mailing worm W32.Salga.
Spreads through e-mail, mIRC, file-sharing networks, and network shares.
Adds the values:
"windows" = "%Windir%\system\system copy.exe"
"system xp" = "%Windir%\acdsee demo.exe"
to Windows startip registry keys.
Creates the file D:\autorun.inf containing the following lines:
[autorun]
open=FUN.ZIP.EXE
Creates the file E:\autorun.inf containing the following lines:
[autorun]
open=Messenger 9.00.ZIP.EXE
Changes the files:
C:\program files\mIRC\script.ini
C:\program files\mIRC32\script.ini
to allow spreading via IRC.
Copies itself as the following:
* %Windir%\acdsee demo.exe
* %Windir%\system\system copy.exe
* %Windir%\system32\egywormo[gen2].exe
* %Windir%\All Users\Desktop\magic\sex photoes of monika.zip.exe
* %Windir%\All Users\Start Menu\Programs\StartUp\salga.b.exe
* %Windir%\Start Menu\mob xp10 net speeder.zip.exe
* %Windir%\start menu\mob xp10 net speeder.zip.exe
* %Windir%\start menu\programs\DR.BLACK PERSON.zip.exe
* %Windir%\start menu\programs\DR.BLACK PERSON chat prog.zip.exe
* C:\BEST 10 SEX MOVIES IN 2004.zip
* C:\hard core hook from web\setup.zip.exe
* C:\magic_cam\magic_cam.ZIP.EXE
* C:\Program Files\Accessories\attachment.zip...............exe
* C:\Program Files\Accessories\Nicole kidman.zip...............exe
* C:\Program Files\mirc\Britny spears marriage with Bnladen son.zip.exe
* C:\Program Files\mirc32\Britny spears marriage with Bnladen son.zip.exe
* C:\Documents and Settings\All Users\DESKTOP\holywood stuff film.zip.exe
* C:\Documents and Settings\All Users\Start Menu\white fang sex.zip.exe
* C:\Documents and Settings\All Users\Start Menu\Programs\sisqoo^^007 progs.zip.exe
* C:\Documents and Settings\All Users\Start Menu\Programs\sisqoo^^007 progs.exe
* C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\a7meedye graphices maker.zip.exe
* C:\Documents and Settings\All Users\Start Menu\Programs\Startup\salga.b.exe
* D:\FUN.ZIP.EXE
* D:\girlfriends emails.zip.exe
* D:\hook all sex movies from webs\setup.zip.exe
* E:\blood of fetch sex.zip.exe
* E:\Messenger 9.00.ZIP.EXE
* E:\real sex telephones\call from me.zip.exe
Adds the value:
"StartKazaa -SilentRun" = "C:\Program Files\Kazaa\My Shared Folder\Shared"
to the registry key:
HKEY_CURRENT_USER\Software\Kazaa\Transfer
Overwrites the Hosts file with the following text, which blocks access to certain Web sites.
Removal: %Windir%\acdsee demo.exe is removed by RegRun.
Read more... Removal instructions...
UnHackMe - Rootkit/Malware killer
Also recommended software:
RegRun Security Suite Platinum - removal and protection.
UnHackMe is a part of RegRun Security Suite Platinum.
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
November 16 2009
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?