<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ankit Kumar Agarwal &#187; virus/antivirus</title>
	<atom:link href="http://ankitkumaragarwal.com/category/virusantivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://ankitkumaragarwal.com</link>
	<description>Hack the way you Think!!</description>
	<lastBuildDate>Thu, 20 May 2010 05:27:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
<link>http://ankitkumaragarwal.com</link>
<url>http://ankitkumaragarwal.com/wp-content/plugins/maxblogpress-favicon/icons/favicon-56.ico</url>
<title>Ankit Kumar Agarwal</title>
</image>
		<item>
		<title>win32:sality Virus</title>
		<link>http://ankitkumaragarwal.com/win32sality-virus/</link>
		<comments>http://ankitkumaragarwal.com/win32sality-virus/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 17:18:00 +0000</pubDate>
		<dc:creator>Ankit Kumar Agarwal</dc:creator>
				<category><![CDATA[virus/antivirus]]></category>

		<guid isPermaLink="false">http://ankitkumaragarwal.com/?p=24</guid>
		<description><![CDATA[I was playing with a few soft wares when my avast antivirus warned me of this &#8220;win32:sality virus&#8221;.As usual i neglected it.This was a big mistake i made.Two hours later my antivirus declared VLC as virus, 4 hours later notepad was declared as virus and 24 hours later almost all exes were declared as virus. [...]]]></description>
			<content:encoded><![CDATA[<p>I was playing with a few soft wares when my avast antivirus warned me of this &#8220;win32:sality virus&#8221;.As usual i neglected it.This was a big mistake i made.Two hours later my antivirus declared VLC as virus, 4 hours later notepad was declared as virus and 24 hours later almost all exes were declared as virus. Many programs terminated abnormally.<br /><span class="fullpost"></p>
<p>I started searching net for information on this virus.When i got the following info about it:-<br /><strong>Characteristics </strong><br /><strong>Type</strong> : Virus<br /><strong>Category</strong> : Win32<br /><strong>Also known as</strong>: W32.HLLP.Sality (Symantec)</p>
<p><a id="section1" name="section1"></a><strong>Description</strong><br />Win32/Sality is a polymorphic virus that infects Win32 PE executable files. It also contains trojan components. Win32/Sality has been known to be downloaded by variants of the Win32/Bagle family.<br /><a id="section2" name="section2"></a><strong>Method of Infection<br /></strong>When an infected file is executed the virus decrypts itself and drops a DLL file into the %System% directory. The DLL file is injected into other running processes. The virus then executes the host program code.<br />Some examples of the names used by the Sality DLL file as reported to CA from the wild include the following:<br /><em>%System%\syslib32.dll<br />%System%\oledsp32.dll<br />%System%\olemdb32.dll<br />%System%\wcimgr32.dll<br />%System%\wmimgr32.dll</em><br />Note: &#8216;%System%&#8217; is a variable location. The malware determines the location of the current System folder by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.<br />Many variants of Sality also attempt to infect executable files referenced by values in the following registry keys:<br />HKLM\Software\Microsoft\Windows\CurrentVersion\RunHKCU\Software\Microsoft\Windows\CurrentVersion\Run<br />This enables the virus to run at each Windows start.<br /><a id="section3" name="section3"></a><strong>Method of Distribution<br /></strong>Via File Infection<br />Sality searches local drives C:\ to Y:\ for Windows PE executable files to infect. Some variants do not infect files with a file size below 4K bytes or above 20M bytes. The virus replaces code at the entry point of the executable with its own code, and appends an encrypted copy of itself to the host file, which increases the size of the infected program. When the file is executed the virus extracts and runs the appended code, and then runs the host program code to hide its presence.<br />Via Network Shares<br />Sality enumerates shares on the network, and then searches located shares for Windows PE executable files in the same way as outlined above on local drives.<br /><a id="section4" name="section4"></a><strong><span style="color: rgb(51, 51, 255);">Payload<br /></span>Steals System Information<br /></strong>Some Sality variants collect information about the infected system and e-mail this information to the domain mail.ru.<br />The information sent includes, but is not limited to, the following:<br />OS version<br />IP address<br />Computer name<br />Recent URLs visited<br />Passwords<br />ISP Dial up Connection details and Password<br /><strong>Downloads and Executes Arbitrary Files<br /></strong>Sality variants contact certain domains which provide instructions to download and execute files, some of the domains contacted are listed below:<br /><em>hut2.ruinvis1blearm</em><br /><em>3333.comegozdq.com</em><br /><em>5558&#215;7.comwtcvxu.com</em><br /><em>fdpgb3.combpfq02.com</em><br /><em>u7zywp.com</em><br /><em>zvco6m.com</em><br /><em>qiredremer.biz</em><br /><em>sbapodremer.biz</em><br /><em>pgpwdremer.biz</em><br /><em>gogcojdremer.biz</em><br /><em>rus0396kuku.com</em><br /><em>vrrnscdremer.biz</em><br /><em>connect2me.org<br /></em>The files downloaded may be used to give a remote unauthorized user extended control of the affected machine. Sality may also download variants of other malware such as Win32/Onecooked.<br />Sality also uses this method to download updated versions of itself.<br /><strong>Deletes files<br /></strong>Sality searches subdirectories on drives C:\ to Y:\ for files with the following extensions:<br />.vdb.avc<br />Files located are deleted. This is presumably to disable or impair certain AV products.<br /><strong>Terminates Processes</strong><br />Sality searches for and terminates any processes which match a list contained in its code; the following is an example of such a list:<br /><em>AVXQUAR<br />ICSUPP<br />ICSSUPPNT<br />ESCANH<br />AVLTMAIN<br />VSMAIN<br />TRJSCAN<br />PROTECTX<br />PORTDETECTIVE<br />PINGSCAN<br />PERISCOPE<br />NPFMESSENGER<br />MCAGENT<br />LOCKDOWN<br />DRWTSN32<br />DRWATSON<br />CLEANER<br />BLACKICE<br />BIPCP<br />BIDSERVER<br />BIDEF<br />AVPROTECT<br />AVGSERV<br />ATGUARD<br />AVSYNMGR<br />AUTOTRACE<br />SAVSCAN<br />RTVSCAN<br />NUPGRADE<br />NPROTECT<br />MGUI<br />MCUPDATE<br />NMAIN<br />ANTI<br />NOD32<br />ZONEALARM<br />OUTPOST<br />DRWEB<br />KAV<br />AVP<br />NAV </em><br />When a processes is terminated Sality displays an error message to indicate a fake error condition.<br /><strong>Logs Keystrokes<br /></strong>Some Sality variants log the affected user&#8217;s keystrokes to a file in the %System% directory. The file name is prefixed with &#8220;win&#8221; followed by random characters, for example:<br />%System%\WINFIGBO.BGO<br />The location of this file is e-mailed to the mail.ru domain.<br /><strong>Changes Firewall Settings<br /></strong>Some Sality trojan components modify the Windows Firewall settings to add themselves as authorized applications. IT was with a name of &#8220;<strong>ipsec</strong>&#8221; in my case.This effectively allows these components to bypass the firewall.In my case my firewall was repeatedly turned off by the virus.<br /><strong>HTTP Proxy<br /></strong>Some Sality variants run an HTTP proxy on port 80 of the affected machine. The trojan contacts the domain shared-admin.com, and receives instructions to connect to the domain connect2me.org, which then returns an IP address. All requests sent to the proxy running on the affected machine are forwarded to the previously returned IP address.<br /><strong>Displays Message</strong><br />Some Sality variants check if the Date is the 10th of October and may display an alarmist message if the hour and the minute have the same value, for example 21:21. Please see below for an example of the message:<br /><em>&#8220;Hey, Lamer! Say &#8220;Bye-bye&#8221; to your data!&#8221;</em><br />After reading it i realised that on how big trouble i have put myself into.I immediately tried my best to remove it:-<br />i)system restore:-didn&#8217;t work soon it was also infected with the virus<br />ii)manually searched for possible dlls:-nothing was found<br />iii)tried sality remover from avg-no use (<a href="http://www.avg.com/virus-removal.ndi-67769">Still Try it</a>)<br />iv)tried safe mode:-it didn&#8217;t boot in safe mode</p>
<p>Finally i had to format my system. So if you get any indication that any software is infected with this virus <strong>do not</strong> install it.There is no way out once your system gets infected with it.So be careful.<br /><span style="font-weight: bold;">Note:-</span>This virus has a special property of hiding in disk partitons. So if you finally decide to format your pc then first delete all drives and then recreate them during installation.</p>
<p><span style="color: rgb(0, 0, 0);">remove virus,antivirus,win32 sality remover,how to remove win32 sality virus.</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://ankitkumaragarwal.com/win32sality-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
