Home Malware Programs Viruses Win32/Sality.nao

Win32/Sality.nao

Posted: December 7, 2010

Threat Metric

Threat Level: 7/10
Infected PCs: 405
First Seen: July 24, 2009
Last Seen: March 19, 2023
OS(es) Affected: Windows

Win32/Sality.nao is a cyber pest designed to dodge security programs and infect computer systems. This virus will try to disable legitimate programs which threaten to kill the infection. Win32/Sality.nao will deviously store itself as a system service with a system name of IPFILTERDRIVER. Win32/Sality.nao infects executable files and files with extension 'scr'. This enables the virus to start whenever Windows is launched. Get rid of Win32/Sality.nao immediately as it will eventually cause the system to malfunction.

Aliases

BackDoor.RBot.LK [AVG]Trojan.Win32.Genome [Ikarus]Backdoor.Agent.AAQO [BitDefender]Trojan.Autorun-303 [ClamAV]W32.Spybot.Worm [Symantec]W32/Sality.AH [Panda]unknown virus Win32/DH{NA} [AVG]Worm.Win32.VB [Ikarus]Heuristic.LooksLike.Win32.Suspicious.J!89 [McAfee-GW-Edition]Trojan.MulDrop1.42002 [DrWeb]BC.Heuristic.Trojan.SusPacked.BF-6.A [ClamAV]Win32.Sality.Y [eSafe]Trojan [K7AntiVirus]W32/Sality.gen.z [McAfee]W32/Sality.AN [Panda]
More aliases (109)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



svchost.exe File name: svchost.exe
Size: 134.14 KB (134144 bytes)
MD5: de19551f6482673aebf394b1715b22e1
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%PROGRAMFILES%\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe File name: varpc.exe
Size: 111.86 KB (111860 bytes)
MD5: 83210205677e8b8081374f2f67fff65d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr
Group: Malware file
Last Updated: July 13, 2011
%WINDIR%\system\VMwareService.exe File name: VMwareService.exe
Size: 1.33 MB (1331200 bytes)
MD5: 7c74db391a16f8aba449248aa45f5c07
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: February 6, 2013
Loading...