W32.Sality Anti Virus

Posted: Jun 25, 2010 |Comments: 0 | Views: 195 |

W32.Sality commonly known as Sality Virus is a malware program which infects exe and scr files thereby spreading as many times the host is executed. This virus also includes an auto run component, as a result of which, it spreads to any removable medium. Moreover this comes with a downloader Trojan component, which downloads and installs more malware when connected to the web.

This virus first appeared in 2003 in Russia. During that time, Sality was a little file infector, which used to prefix its viral code to a host and had back door and key logging facilities. Now it has improvised a lot with more additional features, which has made it more harmful and dangerous. However, Sality's signature has remained the same. Get to know about the virus in detail, get some technical support.

The Characteristics

Symantech.com has nicely explained the features of this virus. The payload runs five distinct components in separate threads.

The first component is a process injector. All processes except those belonging to the users "local service", "network service", or "system", will be injected with a copy of Sality to make sure the malware stays running.

The second component is responsible for lowering or disabling the general security of the system. Security-related processes and services are stopped, including many antivirus and personal firewall products. The registry is modified and SafeBoot key entries are deleted. Components such as registry editing with the Windows regedit.exe tool or Task Manager Creation are disabled. Firewall rules are added to let Sality access the network.

Sality also drops a kernel driver to a dynamically generated location in %System%\drivers and creates a service named "amsint32". This driver is a rootkit, in charge of two things. First, it ends processes when a regular call to TerminateProcess() fails. In fact, the rootkit is able to run dynamic code on to a target process. However, this code, so far, only pertains to process termination.


The second feature is more interesting: the driver sets up an IpFilter callback function to process network packets. Ipfltdrv.sys is a standard Windows driver that can be loaded by starting the IpFilterDriver service. Kernel drivers can set a callback function to be called by IpFilter every time an IP packet goes in or out. The callback can decide to drop the packet. In a few words, IpFilter is a very straightforward way to build a simple Windows firewall. Sality uses the IpFilter to drop every IP packet containing words that belong to an encrypted list of strings that make up security vendor's URLs. The user-mode process can also instruct the driver to drop SMTP packets, blocking traditional email exchange.

The third component is the infector itself. Sality is able to infect files on local drives as well as Windows shares. It also infects files referenced in the HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache registry key, which references the most often-used executables on the system, as well as .exe files located in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. Note here that, the infection routine is efficient enough to check that a file is not protected by the Windows file protection mechanism (SFC) before trying to infect it.

Let's move on to the fourth component: the downloader. Downloading and executing other malware or security risks is the main target of Sality. A compromised host carries with it a list of HTTP URLs that point to resources to be downloaded, decrypted, and executed. These URLs can also point to more URLs. The encryption used here is RC4, with static keys embedded in the compromised host. Now the question is, how are the URLs updated in case some of them get blocked, or more simply, if the malware gang decides to make Sality download other components?

The answer is given by the fifth and final component: its peer-to-peer client and server code. Sality-infected hosts thus become bots of a P2P botnet.

So, it's always good to be extra careful about the virus. If you feel that your PC has been infected W32.Sality virus, call for antivirus support immediately.

The Remedy

•    Call for immediate antivirus support. Scan your PC with an antivirus like Norton, Kaspersky etc. The antivirus should have been updated.
•    Use an anti malware too like malware bytes.
•    Make sure your antivirus is able to delete the infected files. If not, allow the antivirus to do the necessary action.
•    Avoid downloading pirated software.
•    Be careful while opening attachments. Scan it before opening it.
•    Be careful while clicking on links to unknown websites.
•    Use strong password.
•    Avoid social engineering attacks like phishing, Spear phishing, and email hoaxes.

Microsoft has raised the alert level to severe, hence be careful.

List of Aliases

Below is the list of aliases this virus use:

•    Win32/Kashu.B (AhnLab)
•    Win32.Sality.NX (BitDefender)
•    Win32/Sality.W (CA)
•    Win32.Sector.5 (Dr.Web)
•    Win32/Sality.NAO (ESET)
•    W32/Sality.AJ (Frisk (F-Prot))
•    Virus.Win32.Sality.y (Kaspersky)
•    W32/Sality.AE (McAfee)
•    W32/Sality.AO (McAfee)
•    W32/Smalltroj.DXSV (Norman)
•    W32/Sality-AM (Sophos)
•    W32.Sality.AE (Symantec)
•    Win32.Sality.AK (VirusBuster

Questions and Answers

Ask
200 Characters left
Rate this Article
  • 1
  • 2
  • 3
  • 4
  • 5
  • 0 vote(s)
    Feedback
    Print
    Re-Publish
    Source:  http://www.articlesbase.com/computers-articles/w32sality-anti-virus-2726490.html

    Article Tags:

    computer repair

    ,

    tech support

    ,

    computer support

    ,

    computer help

    ,

    computer services

    ,

    online technical support

    ,

    remote tech support

    Concise averted tragic results for hundreds of its business and residential customers with its swift computer trouble shooting software.

    By: Concise Computerl Computers> Data Recoveryl Nov 04, 2009

    Certainly you are getting irritated by your older computer problems. Frequent Internet freezes and computer lags are destroying your sanity. To save your day here are some computer repair tips that can help you in speeding up your old computer.

    By: James Madisonl Computers> Hardwarel May 18, 2010

    Round the clock service, quick in solving the problem, less service charges, expertise in solving different issues and many more are the characteristics of online technical support.

    By: John Singh Petersonl Computers> Softwarel Aug 01, 2011

    This article compares the Pros and Cons involved with Online Computer Repair and local computer repair stores.

    By: Sachin Patill Computersl Oct 07, 2011

    Outsourcing of technical needs have made things much easier than they were earlier. Tech support service provider works round the clock and makes you satisfied with great services that are offered via call or online. You can receive a high level of satisfaction with your online tech support service provider.

    By: George Cullenl Business> Business Ideasl Jan 18, 2010

    Our computer dependency is increasing day by day. So, if your computers malfunction or go wrong on any day, it will definitely deal a great blow to the continuance of our daily life. Better then to know different options about computer repair services.

    By: John Singh Petersonl Computers> Softwarel Aug 10, 2011

    An in depth look at the new MMORPG from Blizzard Entertainment known as Diablo III, a long awaited release for Diablo fans.

    By: swtorman90l Computersl Jun 01, 2012

    Most small businesses take advantage of computer technology, and it certainly can make things a lot easier for everyone within the business when you do so properly. Unfortunately, there are also a number of different problems that can occur as a result of the technology that you are using.

    By: Jesus Mattsonl Computersl May 31, 2012
    Steve Crown

    Copying ipod to computer is easy. For more information on how read this article.

    By: Steve Crownl Computersl May 28, 2012

    Online training software has found its place in almost all the offices and organizations. It can be used to train employees over the net

    By: Yaxley Halel Computersl May 28, 2012

    According to leading research carried out by Gartner, the number of PCs distributed throughout the first quarter of 2012 went up by 1.9% which was better than analysts predicted.

    By: Daniel Kiddl Computersl May 28, 2012

    Want to setup wireless router but don't know how to do it? The process is simple; just you need to follow some steps. Explore this article and get useful tips to setup wireless router.

    By: James Madisonl Computers> Hardwarel Jun 03, 2011

    In order to enjoy safe and secure browsing, there must be adequate protection on your computer. You need to follow a number of security measures for computer virus protection. Go through this article and learn more about them.

    By: James Madisonl Computers> Hardwarel Jun 02, 2011

    Is your computer having startup problem? PC startup problems could occur due to various reasons and different troubleshooting approaches are required to deal with them. Explore this article to get the ways to fix some common startup problems.

    By: James Madisonl Computers> Hardwarel Jun 01, 2011

    Computer problems could crop up anytime without any prior notice. There might be problem with hard drive (HDD), memory (RAM), motherboard & processor (CPU), power supply (PSU) and CD/DVD disc drives. Explore this article and learn how to test for hardware failures.

    By: James Madisonl Computers> Hardwarel May 31, 2011

    Are you formatting your current computer or buying a new PC and thinking which file system to choose? NTFS or New Technology File System is better choice than FAT. Go through this article and learn more about this.

    By: James Madisonl Computers> Softwarel May 30, 2011

    Discuss this Article

    Author Box
    Articles Categories
    All Categories
    Quantcast