Rootkit

Rootkit.Win32.Sality.baka removal guide

Malware Removal

The Rootkit.Win32.Sality.baka is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Sality.baka virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Rootkit.Win32.Sality.baka?


File Info:

name: 7FC61D60D2E43650776B.mlw
path: /opt/CAPEv2/storage/binaries/8cf8165b68246e3ffecdba9410143979324dda5fd99aed587ce0432f6c5fb1a1
crc32: FC9C3128
md5: 7fc61d60d2e43650776bfb8b3f29598e
sha1: 78f98369745d0783d83b79bd0e5324a032365874
sha256: 8cf8165b68246e3ffecdba9410143979324dda5fd99aed587ce0432f6c5fb1a1
sha512: cf72ae41a08a427695d11578ab4c46dbbae430ec4e3f6c3492216c57d280b00a084d3ae7ec87932ff61c2cb64e6ac529ff1676206f085bccb5b6728103fa269e
ssdeep: 384:1t/zfvwxxO/7FANb+dbl+Ai5FGt2pDxFUA0xPQp/Jp2ndJ1peoIFBqu:zznIxy7FAB4bGzZdTRym/vWdJjIL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110234943B78848FBE0E4D6F90D6393225073BE741639CB935DCCBD6F4CBA294A6A4251
sha3_384: 60ac4ec1e8cada4ca53e58ae7c5008b81e03a613b32749f0ff2b56f3a82c3db766ceacb9da383efd46d981df6552db2e
ep_bytes: 60be005042008dbe00c0fdff5783cdff
timestamp: 2008-11-13 17:32:10

Version Info:

0: [No Data]

Rootkit.Win32.Sality.baka also known as:

BkavW32.AIDetect.malware1
DrWebWin32.Sector.12
McAfeeArtemis!7FC61D60D2E4
CylanceUnsafe
VIPREGen:Variant.Zusy.426582
SangforSuspicious.Win32.Save.ins
BitDefenderGen:Variant.Zusy.426582
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34698.dmW@aSH8aCf
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Sality.NAR
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.GenericML.xnet
MicroWorld-eScanGen:Variant.Zusy.426582
RisingBackdoor.Cylent!1.A239 (CLASSIC)
Ad-AwareGen:Variant.Zusy.426582
SophosML/PE-A
BaiduWin32.Trojan.Sality.j
McAfee-GW-EditionBehavesLike.Win32.Generic.pt
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7fc61d60d2e43650
EmsisoftGen:Variant.Zusy.426582 (B)
IkarusVirus.Win32.Sality
JiangminTrojan/Vilsel.aakf
AviraRKIT/Sality.A
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Zusy.426582
GoogleDetected
AhnLab-V3Trojan/Win32.Vilsel.R90523
VBA32Rootkit.Win32.Sality.baka
ALYacGen:Variant.Zusy.426582
MAXmalware (ai score=88)
MalwarebytesMalware.AI.4255551949
APEXMalicious
TencentTrojan.Win32.Vilsel.aab
MaxSecureTrojan.Malware.185628869.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.9745d0
AvastWin32:Malware-gen

How to remove Rootkit.Win32.Sality.baka?

Rootkit.Win32.Sality.baka removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment