Sality Virus
Malware - Viruses

W.32 Sality is a complex virus which installs a keylogger and a backdoor. The virus installs itself in the system, checks the current time and runs a payload if the time is such that the "hours are equal to minutes" or "if it is a particular date".


The Sality virus infects local executable files, deletes files of security-related software such as antiviruses and firewalls. Then it runs a keylogger which collects system and network information, records user login names and passwords, steals sensitive information stored in specific files and finally sends all this data to the hacker's e-mail address.

Sality can also open a back door providing the hacker with unauthorized access to the computer. The hacker can then control the computer and can steal other sensitive information. It is also described as a virus capable to modify other files by infecting, prepending, or overwriting them them with its own body.

It has different variations, i will list the detailed info about them.

 

 Manually Editing the Registry:

 

You can edit the registry by using the windows built in registry editor. Click on Start > Run to open the run command box in XP, whereas in Vista the box is already open. type regedit and press Enter or Ok , that will open the registry editor. Now Click on Edit > Find. You can use this box to find a particular registry key/ value. In order to do that, copy the last part of the registry keys if they are inside curly braces {}, after the last / (forward slash) and then paste it into this box, or type in the name of the malware in the box and press "Find Next", if the search stops , you should either see a message saying "Finished searching through the registry"or it will stop at that key found. The found item will be displayed in blue selection. You can delete the entire key, that is the entry in the left side of the panel, once you confirm yourself that this key belongs to the malware by looking at the entire key and comparing it with the ones listed here, and by looking at the values that it has created in the right side of the panel. In case you are not sure if you want to remove the key, you can remove the values in the right side panel instead, that will also cripple the functioning of the malware. To delete a key/ value, use the mouse pointer to select it first, then right click on it to see a menu and select delete from it, then say yes to the confirmation alert. Alternately you can press the delete key on the keyboard to delete the selected entry.  You can also use the names of the files / folders created by the malware to search for their associated keys in the registry.

Once you have deleted an entry, press the F3 key on the keyboard to search for the next occurance of the entry, do this till you reach the end of the registry. Now copy the second registry key/ filename and repeat the above procedure. This is a tedious process and takes time  and effort, but there is no better way to make sure the malware is out of your computer. 

Varitaion 1)  See the ThreatExpert report

-Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode.
-Modifies some system settings that may have negative impact on overall system security state.

   Modified the following file. These are legitimate windows system files. Use the system file checker utility  to repair these files.

    C:\Windows\system.ini
    C:\Windows\System32\ctfmon.exe
    C:\Windows\System32\mmc.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\taskmgr.exe


Creates its own process in place of a windows process
C:\Windows\System32\dllhost.exe   

Creates its own kernel-mode drivers in place of windows drivers
C:\Windows\System32\drivers\ipfltdrv.sys
C:\Windows\System32\drivers\iksnpn.sys

These are all legitimate windows files/processes/drivers, that it replaces. Therefore it will be very difficult to remove them if you are doing on a running windows.  The best way to eliminate it would be to do a boot scan using a currenty updated antivirus, or attach the infected hard disk to another computer and then scan it .  One thing that you can probably do on the infected computer is to remove the registry entries created by this virus , by manually editing the registry. Altough if there is any process of the virus currenlty running, it will try to recreate the deleted folders/ files and rewrite the registry entries. You will need a software that will alert you as soon as any process tries to modify the registry, that will help you to prevent further infection of the registry as you delete these keys. You can use Spybot S&D with Teatimer. Teatimer is the component that alerts you as soon as some process tries to midify the registry, and lets you Allow or Deny the changes. Here is a list of the registry keys created by this particular varitaion of Sality
     HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5\0000
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5\0000\Control
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Security
     HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Enum
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5\0000
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5\0000\Control
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Security
     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Enum
     HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system
     HKEY_CURRENT_USER\Software\%UserName%914
     HKEY_CURRENT_USER\Software\%UserName%914\-72398023

It deletes the registry keys of the Safeboot, therefore you will not be able to boot in safe mode. Doing a repair installation of windows can make your computer workable. 

 

Variation2)  see the threatexpert report

 Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode. Creates a startup registry entry.

Creates the follwing file in the computer. Delete it. Running a temp files cleaner will wipe it out automatically.
C:\Documents and Settings\[UserName]\Local Settings\Temp\services.exe
Modifies the following files. These are legitimate files, do not delete them. You need to run the system file checker utility to repair the infected files.
     C:\Windows\NOTEPAD.EXE
     C:\Windows\system.ini
     C:\Windows\System32\cmd.exe
     C:\Windows\System32\ctfmon.exe
     C:\Windows\System32\mmc.exe
     C:\Windows\System32\notepad.exe
     C:\Windows\System32\rundll32.exe
     C:\Windows\System32\taskmgr.exe

Creates new kernel mode drivers, dlete them if found.
C:\Windows\System32\drivers\ipfltdrv.sys
C:\Windows\System32\drivers\imjnhn.sys

There are a number of registry modifications, which you can find in the threatexpert report. 

 Variation3) Similar to variation2 except different registry modicications . See threatexpert report.
     HKEY_CURRENT_USER\Software\Microsoft\Telnet
     HKEY_CURRENT_USER\Software\%UserName%914
     HKEY_CURRENT_USER\Software\%UserName%914\-72398023

 

 

Comments
Add New Search
Write comment
Name:
Email:
 
Title:
 

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

 
Privacy Policy