W32/Sality.ao is a parasitic virus that infects Win32 PE executable files. It infects files (*.exe and *.scr files) on the local, network and removable drives by overwriting code in the entry point of the original file and saving the overwritten code in its virus body. It then appends the virus body to the host file.
|
Minimum DAT
5389 (2008-09-22) Updated DAT5760 (2009-10-03) |
Minimum Engine
5400.1158 File Lengthvaries |
Description Added
2008-09-22 Description Modified2008-09-26 |
W32/Sality.ao is a parasitic virus that infects Win32 PE executable files. It infects files (*.exe and *.scr files) on the local, network and removable drives by overwriting code in the entry point of the original file and saving the overwritten code in its virus body. It then appends the virus body to the host file.
Upon infection creates the following mutexes to ensure that only one instance of the virus is active on a computer at any time.
Disables Regedit and Task Manager by modifying the following registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system "DisableRegistryTools"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system "DisableTaskMgr"
Disable XP Security Center by modifying the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "UacDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "UpdatesDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "AntiVirusDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "AntiVirusOverride"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "FirewallDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "FirewallOverride"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "UacDisableNotify"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc "UpdatesDisableNotify"
Downloads further malware from the following domains:
Adds the following entries in the SYSTEM.INI file:
[MCIDRV_VER]
DEVICEMB={Random numbers}
W32/Sality.ao searches local drives, removable and network shares for Windows PE executable files to infect. It replaces the original entry point of the files it infects with its viral code and appends itself to the last section of the PE image.
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.