W32/Sality-H is a virus that also acts as a keylogger
W32/Sality-H logs keystrokes to certain windows making use of SYSLIB32.DLL which it first drops in the System or Temp folder. This keylog is then sent in emails using the virus' own SMTP engine along with other detailed information gathered from the computer.
On the 10-12th of the month, when the minute equals the hour, the following message is displayed with the title 'Win32.HLLP.Kuku v2.91':
<<<<<Hey, Lamer! Say "Bye-bye" to your data! >>>>>
Copyright (c) by Sector'