Sophos

W32/Sality-AM

Aliases
  • Win32/Sality.gen
  • W32/Sality.dll
  • New Win32.s
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Included in our products from July 2008 (4.31)
Protection available since 15 January 2008 07:26:45 (GMT)
Last updated 16 May 2008 23:11:28 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sality-AM is a virus for the Windows platform.

The virus includes the functionality to download additional files from a remote location.

When first run, the virus may infect executables in the root folder, files on network shares, and files it may find based on the following registry locations:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache

W32/Sality-AM may install the following file:

<System>\<random>.sys

This file is detected as Troj/RkSal-A

W32/Sality-AM may set registry entries under:

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80

W32/Sality-AM may delete registry entries under:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\

Due to errors in the viral infection code, some files may be corrupted by W32/Sality-AM so that they won't run. Some but not all of these files are still disinfectable, although W32/Sality-AM always overwrites data appended to files during infection so this will never be recoverable.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer