Malware

Mal/Sality-D (file analysis)

Malware Removal

The Mal/Sality-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Sality-D virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ddos.dnsnb8.net

How to determine Mal/Sality-D?


File Info:

crc32: A3F16AC8
md5: ce0ee4d37ac6d28688423f839492828d
name: friends.exe
sha1: c89a3abfc2ff6385befbb36014293ed42e93b662
sha256: 0d05382047ea345213ed809638670a795f806b547675468cb4c47e1f3c31d3ad
sha512: d1bdec3961ade823306d2b9d9ab1badfc9685134b32675d4ac94f36f68e46341d30ed4ff4f22829003fdef9125bb1c9bcd0d8f924ef1e543ea68123a80e49414
ssdeep: 6144:PHjYNzlQhULkL5t5CQLkjvfadtzpjr4JTfymphzv8:PjYBlRkAEkjw18UEx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Ontrack
FileVersion: 12.0.0.2
CompanyName: Ontrack
Comments: This installation was built with Inno Setup.
ProductName: Ontrackxae EasyRecoveryx2122 Home for Windows
ProductVersion: 12.0.0.2
FileDescription: Ontrack
Translation: 0x0000 0x04b0

Mal/Sality-D also known as:

BkavW32.Sality.PE
MicroWorld-eScanWin32.Sality.3
CAT-QuickHealW32.Sality.U
Qihoo-360Virus.Win32.Sality.I
McAfeeW32/Sality.gen.z
CylanceUnsafe
ZillyaVirus.Sality.Win32.25
SangforMalware
K7AntiVirusVirus ( f10001071 )
BitDefenderWin32.Sality.3
K7GWVirus ( f10001071 )
Cybereasonmalicious.37ac6d
TrendMicroPE_SALITY.RL
BaiduWin32.Virus.Sality.gen
F-ProtW32/Sality.gen2
SymantecW32.Sality.AE
ESET-NOD32Win32/Sality.NBA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Downloader-64720
KasperskyVirus.Win32.Sality.gen
AlibabaVirus:Win32/Sality.3cae245c
NANO-AntivirusVirus.Win32.Sality.beygb
ViRobotWin32.Sality.Gen.A
AvastWin32:Rootkit-gen [Rtk]
TencentVirus.Win32.TuTu.tv
Ad-AwareWin32.Sality.3
EmsisoftWin32.Sality.3 (B)
ComodoVirus.Win32.Sality.gen@1egj5j
F-SecureMalware.W32/Sality.AT
DrWebWin32.Sector.30
VIPREVirus.Win32.Sality.at (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ramnit.hm
FortinetW32/Sality.BH
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ce0ee4d37ac6d286
SophosMal/Sality-D
SentinelOneDFI – Malicious PE
CyrenW32/Sality.gen2
JiangminWin32/HLLP.Kuku.poly2
AviraW32/Sality.AT
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Sality.gen
Endgamemalicious (high confidence)
ArcabitWin32.Sality.3
ZoneAlarmVirus.Win32.Sality.gen
MicrosoftVirus:Win32/Sality.AT
AhnLab-V3Win32/Kashu.E
Acronissuspicious
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
TACHYONVirus/W32.Sality.D
VBA32Virus.Win32.Sality.bakc
MalwarebytesSpyware.Socelars
ZonerTrojan.Win32.Sality.22009
TrendMicro-HouseCallPE_SALITY.RL
RisingMalware.Heuristic!ET#79% (RDMK:cmRtazqkWOl1A1zGpDsuRn8KqiBM)
YandexWin32.Sality.BL
IkarusTrojan.Win32.Farfli
eGambitUnsafe.AI_Score_99%
GDataWin32.Virus.Sality.A
AVGWin32:Rootkit-gen [Rtk]
PandaW32/Sality.AA
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.Sality.BH

How to remove Mal/Sality-D?

Mal/Sality-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment