Malware

ML/PE-A + Troj/SalLoad-C removal guide

Malware Removal

The ML/PE-A + Troj/SalLoad-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/SalLoad-C virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Installs a browser addon or extension
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to block SafeBoot use by removing registry keys
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Troj/SalLoad-C?


File Info:

crc32: 711409A0
md5: 0e50b608ff22d9b7c4199ac70ac2c907
name: 0E50B608FF22D9B7C4199AC70AC2C907.mlw
sha1: f2250577ca2aab66b98cb9ed6b18d25f170b768d
sha256: 2587e54017f3a8c968e9bf25a6ca69fae6d5f840b23bbac4e4a37c7a7497e02e
sha512: 22b58582d7a3bc40f3d35f892264b72dd41ef54c85bb1b5fbe5e25b1eb42299c887d0ee41812d16185cfd8872cc6e61967cfb22fe57fe42055b6987a77fab822
ssdeep: 1536:tQI4tCDyziDO5HNZ3H3PwgyzURLb6duLCg6UgWGTrZU+gDa2Re6bOm:t3UCDyzdHZ3P5yzob64CmwZ6e28a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/SalLoad-C also known as:

BkavW32.Sality.PE
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Agent-36126
FireEyeGeneric.mg.0e50b608ff22d9b7
CAT-QuickHealW32.Sality.U
McAfeeW32/Sality.gen.z
CylanceUnsafe
ZillyaVirus.Sality.Win32.17
SangforWin.Trojan.Agent-36126
K7AntiVirusTrojan ( 001cddbb1 )
BitDefenderWin32.Sality.3
K7GWTrojan ( 001cddbb1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Sality.p
CyrenW32/Sality.gen2
SymantecW32.Sality!dr
TotalDefenseWin32/Sality.AA
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Sality.gen
NANO-AntivirusVirus.Win32.Sality.beygb
ViRobotWin32.Sality.N.Host
MicroWorld-eScanWin32.Sality.3
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazpoWe6chFF3f87iwjTK34SV)
Ad-AwareWin32.Sality.3
SophosML/PE-A + Troj/SalLoad-C
ComodoVirus.Win32.Sality.gen@1egj5j
F-SecureMalware.W32/Sality.AT
DrWebWin32.Sector.31
VIPREVirus.Win32.Sality.at (v)
TrendMicroPE_SALITY.RL-O
McAfee-GW-EditionBehavesLike.Win32.Ardurk.cc
EmsisoftWin32.Sality.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/HLLP.Kuku.poly2
AviraW32/Sality.AT
MAXmalware (ai score=87)
Antiy-AVLVirus/Win32.Sality.gen
MicrosoftVirus:Win32/Sality.AT
ArcabitWin32.Sality.3
SUPERAntiSpywareTrojan.Agent/Gen-CDesc[Gen]
ZoneAlarmVirus.Win32.Sality.gen
GDataWin32.Sality.3
AhnLab-V3Win32/Kashu.E
Acronissuspicious
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
ALYacWorm.Sality.3.Gen
TACHYONVirus/W32.Sality.D
VBA32Virus.Win32.Sality.bakc
MalwarebytesTrojan.MalPack.Gen
PandaW32/Sality.AK.drp
ESET-NOD32Win32/Sality
TrendMicro-HouseCallPE_SALITY.RL-O
TencentTrojan.Win32.SalityStub.a
YandexTrojan.GenAsa!gQiCZ6kxGcc
IkarusVirus.Win32.Sality
MaxSecureTrojan.LordPE
FortinetW32/LPECrypt.A!tr
AVGWin32:Sality [Inf]
Cybereasonmalicious.8ff22d
AvastWin32:Sality [Inf]
Qihoo-360Trojan.Win32.SalityStub.A

How to remove ML/PE-A + Troj/SalLoad-C?

ML/PE-A + Troj/SalLoad-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment