Malware

Dropped:Win32.Sality.RA (B) removal instruction

Malware Removal

The Dropped:Win32.Sality.RA (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Win32.Sality.RA (B) virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Win32.Sality.RA (B)?


File Info:

name: 9F34CC12EE4AC64B95F7.mlw
path: /opt/CAPEv2/storage/binaries/ac7a023f0fa18159378610b460c407c775b45a5f9ac95bc8d661b4178a4c0836
crc32: 5BF40A19
md5: 9f34cc12ee4ac64b95f7a38836578ee7
sha1: 3ae6d3645b33bcdb8761d463522cbf70e7388ec3
sha256: ac7a023f0fa18159378610b460c407c775b45a5f9ac95bc8d661b4178a4c0836
sha512: 7d4a14abc2467e903b69f91bae1dabdee4cc7a08b7e5e72e8272c5c5293177ac3b94069d9bba3f09c0ce1ef2a11037731865246f28e13f58cc7a7a7d9a8528cc
ssdeep: 3072:reN0LwH/hUmnWac5jglEWWqDHwf1O4oSZdIW/834ip6P3zPPMpSE:reNxPopWWqLo9oSZbiU/z2SE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164E36C1232F98934F4F23EB89BBC95218A75BCA16F35D3DF2240565F5A70A948D30B27
sha3_384: 32e520664ad8b4575667670eab91c38423dce6c7a29c7b3cac0427c2a6f59cf809f917d26df827b932a09d9e2559f6d8
ep_bytes: 60e8000000005883e83d508db800b0fc
timestamp: 2003-09-28 00:37:23

Version Info:

0: [No Data]

Dropped:Win32.Sality.RA (B) also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Krepper.l3gW
tehtrisGeneric.Malware
DrWebWin32.HLLP.Sector.30760
MicroWorld-eScanDropped:Win32.Sality.RA
FireEyeGeneric.mg.9f34cc12ee4ac64b
CAT-QuickHealW32.Sality.F
SkyhighBehavesLike.Win32.Mytob.ch
McAfeeW32/Sality.i.gen
Cylanceunsafe
ZillyaVirus.Krepper.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 000e341a1 )
AlibabaVirus:Win32/Krepper.5919c3ee
K7GWVirus ( 000e341a1 )
Cybereasonmalicious.2ee4ac
BitDefenderThetaAI:Packer.95B599291F
VirITWin32.Sality.F
SymantecW32.Sality
Elasticmalicious (high confidence)
ESET-NOD32Win32/Sality.H
APEXMalicious
TrendMicro-HouseCallPE_SALITY.L
ClamAVWin.Trojan.Kreepper-1
KasperskyVirus.Win32.Krepper.30760
BitDefenderDropped:Win32.Sality.RA
NANO-AntivirusVirus.Win32.Krepper.getc
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.Krepper.a
EmsisoftDropped:Win32.Sality.RA (B)
F-SecureMalware.W32/Krepper.30761
VIPREDropped:Win32.Sality.RA
TrendMicroPE_SALITY.L
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusVirus.Win32.Krepper
JiangminWin32/Krepper.a
GoogleDetected
AviraW32/Krepper.30761
VaristW32/Krepper.WYNG-6962
Antiy-AVLVirus/Win32.Krepper.btnc
KingsoftWin32.Krepper.a.30760
MicrosoftVirus:Win32/Krepper.30760
XcitiumVirus.Win32.Krepper.30760@14400g
ArcabitWin32.Sality.RA
ZoneAlarmVirus.Win32.Krepper.30760
GDataDropped:Win32.Sality.RA
CynetMalicious (score: 100)
AhnLab-V3Win32/Sality.O
VBA32Virus.Win32.Krepper.30760
ALYacDropped:Win32.Sality.RA
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Sality.K
ZonerProbably Heur.ExeHeaderL
RisingWin32.Krepper.a (CLASSIC)
YandexTrojan.GenAsa!dUDSOmJHLTo
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Krepper.30760
FortinetW32/Sality.AC
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirus:Win/Sality.LAYDA

How to remove Dropped:Win32.Sality.RA (B)?

Dropped:Win32.Sality.RA (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment