FRISK Software International


Summary of W32/Sality.AC
Discovered: 7 Jul 2006
Definition files: 7 Jul 2006
Risk Level: Medium
Distribution:Low
 
Jump to:
Brief description
Technical description
Removal Instructions

Brief Description
W32/Sality.AC is a mass-mailing worm and a file infector based on an older version of the virus W32/Sality.J. It tries to spread via P2P networks and network shares, downloads and executes files from the Internet and infects executable files.


Technical Description
Upon first execution the worm copies itself to %SYSDIR%\lmovie.exe and drops the files %SYSDIR%\olemdb32.dll (detected as W32/Sality.J) and %WINDIR%\vcualts32.exe (detected as W32/Bagle.EG@dl). The files %SYSDIR%\lmovie.exeopen and %SYSDIR%\lmovie.exeopenopen (both detected as W32/Sality.AC) may also be droped. Then, before it terminates, it executes the files vcualts32.exe and lmovie.exe.

Note: %SYSDIR% refers to the System directory. The default path for the respective operating systems is as follows:
  • Windows 95/98/Me - C:\Windows\System
  • Windows NT/2000 - C:\Winnt\System32
  • Windows XP - C:\Windows\System32

It adds the value:

"MovieM"="%SYSDIR%\lmovie.exe"

to the key:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

to make sure it is executed at startup.

Creates copies of itself under the following names:

anna benson sex video.exe
kate beckinsale nude pictures.exe
jenna elfman sex anal deepthroat
miss america Porno, sex, oral, anal cool, awesome!!.exe
Porno Screensaver.scr
Serials.txt.exe
barrett jackson nude photos, movies, porn video.exe
Britney Spears sex photos.exe
paris hilton Porno pics arhive, xxx.exe
Windows Sourcecode update.doc.exe
Ahead Nero 10.exe
Windown Vista Beta Leak.exe
IE beta 7.exe
Serials 2005 database.exe
XXX hardcore images.exe
Adobe Photoshop 9 full.exe

in all directories containing the string "shar" in their name. This is done in an attempt to spread via P2P networks and network shares.

It infects all suitable excutables it finds. All infected files are detected as W32/Sality.J. The file %SYSDIR%\olemdb32.dll is embedded in the infected files.

The file %WINDIR%\vcualts32.exe tries to download and execute files from the Internet.

Harvests e-mail addresses from files having the following extensions:

.wab
.txt
.msg
.htm
.shtm
.stm
.xml
.dbx
.mbx
.mdx
.eml
.nch
.mmf
.ods
.cfg
.asp
.php
.pl
.wsh
.adb
.tbb
.sht
.xls
.oft
.uin
.cgi
.mht
.dhtm
.jsp

Sends itself as an attachment to harvested addresses.

The e-mail has one of the following subjects:

Will You Be My Valentine?
Love you with all my heart!
See you tonight!
Come Be With Me, my Love!
My dream is coming true!

The attachment has one of the following names:

love_me
mplay
love_me_now

Avoids sending itself to e-mail addresses having one of the following substrings:

@hotmail
@msn
@microsoft
rating@
f-secur
news
update
anyone@
bugs@
contract@
feste
gold-certs@
help@
info@
nobody@
noone@
kasp
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
sopho
@foo
@iana
free-av
@messagelab
winzip
google
winrar
samples
abuse
panda
cafee
spam
pgp
@avp.
noreply
local
root@
postmaster@


Removal Instructions
For general removal instructions please click here.

Marteinn Žór Haršarson
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is