Home Malware Programs Viruses Win32.Sality.OG

Win32.Sality.OG

Posted: October 17, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 98
First Seen: October 17, 2011
OS(es) Affected: Windows

Win32.Sality.OG is a harmful computer virus, which is a polymorphic rootkit-installing file infector. Win32.Sality.OG proliferates via network shares and removable disk drivers. Win32.Sality.OG modifies .exe and .scr executable files by adding its encrypted body at the end of the files in a newly generated section. To reach the execution of this, the original code from the entry point is also changed with polymorphic sequences which held in the decryption routine. Remove Win32.Sality.OG immediately upon detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 172.54 KB (172543 bytes)
MD5: bfc1acba91e1b9fc871c2f590c263043
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 18, 2011
file.exe File name: file.exe
Size: 105.34 KB (105341 bytes)
MD5: 68e9cda1f17be7588e6a156fefa6ccdb
Detection count: 27
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 18, 2011
file.exe File name: file.exe
Size: 110.9 KB (110904 bytes)
MD5: 9b429cef9da822467dfed6eaab73f981
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 18, 2011
file.dll File name: file.dll
Size: 421.16 KB (421160 bytes)
MD5: d1b99217b4a6c2a84103e7e873811228
Detection count: 24
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: October 18, 2011
file.exe File name: file.exe
Size: 176.45 KB (176456 bytes)
MD5: deb876d78178932c373a088d550d3268
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 18, 2011
%System%\drivers\[random_name].sys File name: %System%\drivers\[random_name].sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKLM\System\CurrentControlServices\asc3360pr
Loading...