Virus.Win32.Sality

GPTKB entity

Statements (39)
Predicate Object
gptkbp:instanceOf gptkb:virus
gptkbp:abilities downloads additional malware
disables security software
steals sensitive information
joins infected computers to botnet
spreads to other computers
gptkbp:affectsFileTypes .dll
.exe
.scr
gptkbp:alsoKnownAs gptkb:Sality
gptkbp:category gptkb:virus
malware
trojan
rootkit
gptkbp:detects gptkb:Kaspersky
gptkb:ESET
gptkb:Symantec
gptkb:Microsoft_Defender
gptkbp:discoveredBy 2003
https://www.w3.org/2000/01/rdf-schema#label Virus.Win32.Sality
gptkbp:notableFeature peer-to-peer communication
injects code into processes
polymorphic code
modifies system registry
terminates security processes
gptkbp:notableVariant gptkb:Sality.AM
gptkb:Sality.N
Sality.Y
gptkbp:platform gptkb:Microsoft_Windows
gptkbp:removalDifficulty difficult
gptkbp:removalToolAvailable Yes
gptkbp:spreadTo removable drives
network shares
infected executable files
gptkbp:usesMalware botnet
rootkit
file infector
gptkbp:bfsParent gptkb:Sality
gptkbp:bfsLayer 7