W32/Sality.AA

Alias/esVirus.Win32.Sality.ab (KAV), W32/Sality.ad (McAfee), W32/Sality.AN (Panda)
Release DateJul 16, 2008
Detection Availability
Active DatabaseExtended Database
FortiGatelowhigh
FortiClient
FortiMailN/A
Current Antivirus Definition Database Version: 12.308
Description

Visible Symptoms

  • The following files exist in the System folder:

    • st114421.dll
    • st114421.dl_



Detailed Analysis


  • This is a polymorphic virus that infects files that have the EXE and SCR extension names.

  • Drops the following files in the System folder:

    • st114421.dll
    • st114421.dl_

    These files are both detected as W32/KillAV.NH!tr.

  • Drops the file [Random].sys  in the %System%\drivers folder. This file is detected as W32/KillAV.NE!tr.

Description Last Updated Date: Sep 23, 2009
Reference: ID - 511936