Home Malware Programs Viruses Win32.Sality.AA

Win32.Sality.AA

Posted: May 4, 2010

Threat Metric

Threat Level: 7/10
Infected PCs: 79
First Seen: July 24, 2009
OS(es) Affected: Windows

Win32.Sality.AA is a network-aware worm that attempts to replicate across an existing network. Win32.Sality.AA requests other malicious files from the Internet and has the ability to send out email messages with a built-in SMTP client engine which can send private emails directly to a recipient mail server for malicious purposes. Win32.Sality.AA contains definite characteristics of an identified security risk and should be terminated immediately.

Aliases

BKDR_SALITY.AJ [TrendMicro]W32.HLLP.Sality [Symantec]W32/Sality-W [Sophos]W32/Sality.P [Panda]Virus:Win32/Sality.O.dll [Microsoft]W32/Sality.dll [McAfee]W32/Sality [Fortinet]Virus.Win32.Sality.k [F-Secure]Win32/Sality.N [eTrust-Vet]Win32.Sality.gen [eSafe]Win32.HLLP.Sector [DrWeb]W32.Sality-2 [ClamAV]Win32.Sality.G [BitDefender]Win32/Sality [AVG]Win32:Sality-AI [Avast]
More aliases (23)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



wcmlogon.dll File name: wcmlogon.dll
Size: 24.57 KB (24576 bytes)
MD5: 3c2a09832c83498e3bae458c84175377
Detection count: 25
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
Loading...