Trojan

Salgorea.Trojan.Dropper.DDS removal guide

Malware Removal

The Salgorea.Trojan.Dropper.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Salgorea.Trojan.Dropper.DDS virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Salgorea.Trojan.Dropper.DDS?


File Info:

name: 97072CC012A15B97099A.mlw
path: /opt/CAPEv2/storage/binaries/c8b01cd7534997425e83f51921f7de171993a88074334e8eb071eb7ff999ec9e
crc32: E5698041
md5: 97072cc012a15b97099af136c992f179
sha1: ee47366eb31ad52663351a7ba6138fea91b98467
sha256: c8b01cd7534997425e83f51921f7de171993a88074334e8eb071eb7ff999ec9e
sha512: 514792c21ea215955768f4fe87874710ccc00dfe8ee1f38236085ce1d956c77a59fd9b49fe00c16b8c5b39a216bc23f2d9ceec9a1386723cd02c8fdb714160ab
ssdeep: 12288:VW0GZMs9JNuOA8pBRQJnKRLyFatfx4/weXuN2G/9:VW009JkUByJnKRtmVXjG/9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5D4011532A1E3B3F16304326A58CBA22D3E7A364F356DD7B3D1465DBD206C09A70BA3
sha3_384: 86155084a458b0eff2664e77be884f093902112c092d7708d8ef374e5373ace364745aa5298ff417a8d94a5fa87685f8
ep_bytes: e807400000e97ffeffffe9a0170000cc
timestamp: 2013-03-07 02:48:43

Version Info:

0: [No Data]

Salgorea.Trojan.Dropper.DDS also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.317902
ClamAVWin.Malware.Bskd-9753126-0
CAT-QuickHealBackdoor.GenericPMF.S20367522
McAfeeGenericR-DWL!97072CC012A1
MalwarebytesSalgorea.Trojan.Dropper.DDS
ZillyaDropper.Agent.Win32.203303
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004c27cf1 )
K7GWTrojan ( 004c27cf1 )
Cybereasonmalicious.012a15
CyrenW32/S-1893685f!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Salgorea.V
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.317902
NANO-AntivirusTrojan.Win32.Salgorea.dsghmg
SUPERAntiSpywareTrojan.Agent/Gen-Salgorea
AvastWin32:Agent-AYZG [Cryp]
TencentMalware.Win32.Gencirc.10bc0ba3
TACHYONTrojan/W32.Agent.634368.EI
EmsisoftGen:Variant.Zusy.317902 (B)
F-SecureHeuristic.HEUR/AGEN.1318588
DrWebTrojan.Siggen8.42740
VIPREGen:Variant.Zusy.317902
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.97072cc012a15b97
SophosTroj/AutoG-DT
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.317902
JiangminTrojan/Agent.ihvi
AviraHEUR/AGEN.1318588
Antiy-AVLTrojan[Dropper]/Win32.Agent
XcitiumTrojWare.Win32.Salgorea.RHG@7yqza3
ArcabitTrojan.Zusy.D4D9CE
ZoneAlarmHEUR:Backdoor.Win32.Generic
MicrosoftTrojan:Win32/Salgorea.C!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R418782
BitDefenderThetaGen:NN.ZexaF.36250.MqW@aKhtCKci
ALYacGen:Variant.Zusy.317902
MAXmalware (ai score=82)
VBA32BScope.TrojanDropper.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Salgorea!1.BAEC (CLASSIC)
IkarusTrojan.Win32.Salgorea
FortinetW32/Generic.AC.B53CC!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Salgorea.Trojan.Dropper.DDS?

Salgorea.Trojan.Dropper.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment