Malware

Troj/Salgorea-D information

Malware Removal

The Troj/Salgorea-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Salgorea-D virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Salgorea-D?


File Info:

name: 31491BF14648E0B8BAA2.mlw
path: /opt/CAPEv2/storage/binaries/d3d93c6501ecdfe34c5baf7e32983f72348e8a8a7006857f9297c201e178b8a8
crc32: 27DCE2AB
md5: 31491bf14648e0b8baa2a54574f40736
sha1: efa437c5c67a44e13969f919c6361e372a900ad0
sha256: d3d93c6501ecdfe34c5baf7e32983f72348e8a8a7006857f9297c201e178b8a8
sha512: 4d56290e71ce645639047955db4c7db57987d0b9db200b7e27f9bef5d62e8440683ff2b75ecd24430938e1c6fd567b1831bd5c180ca4f22cdc51cacb4a73a522
ssdeep: 12288:HU5rCOTeiJ92X3yEjiyqGyCgiQEdlROgvNZ:HUQOJJ9gCE21GywpdRN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180B4F125B585C036E69201704EE6EFA2693A7D714B22A0C77BC4737E6FB02D197B5307
sha3_384: 383ed6a47d5aa8dc0fb1119ef686fd7fc8e735a1cd0246ac652a36d61bdc0007602e706d9bae82098535ee018053b0e4
ep_bytes: e90cec05000000000000000000000000
timestamp: 2003-11-11 14:39:16

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Troj/Salgorea-D also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95989
ClamAVWin.Trojan.Cuegoe-6336261-0
FireEyeGeneric.mg.31491bf14648e0b8
CAT-QuickHealTrojan.GenericRI.S28930490
McAfeeGenericRXHF-BX!31491BF14648
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0043c2cb1 )
K7GWTrojan ( 0043c2cb1 )
Cybereasonmalicious.14648e
ArcabitTrojan.Generic.D176F5
BitDefenderThetaGen:NN.ZexaF.36196.Ey0@aasXdhbi
CyrenW32/Upatre.OL.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Agent.tevevx
BitDefenderTrojan.GenericKDZ.95989
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Agent-AYZG [Cryp]
TencentTrojan.Win32.Salgorea.ya
TACHYONTrojan-Dropper/W32.Agent.499200.L
SophosTroj/Salgorea-D
BaiduWin32.Trojan-Dropper.Agent.ab
F-SecureHeuristic.HEUR/AGEN.1315087
DrWebTrojan.Siggen6.61639
VIPRETrojan.GenericKDZ.95989
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.95989 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.gqlz
AviraHEUR/AGEN.1315087
Antiy-AVLTrojan/Win32.AGeneric
XcitiumApplication.Win32.Amonetize.NE@5te978
MicrosoftTrojan:Win32/Salgorea.A!MTB
ZoneAlarmTrojan-Dropper.Win32.Agent.tevevx
GDataWin32.Trojan.PSE.168GMQ4
GoogleDetected
AhnLab-V3Malware/Win.Generic.R513806
Acronissuspicious
VBA32TrojanDownloader.Upatre
ALYacTrojan.GenericKDZ.95989
MAXmalware (ai score=84)
MalwarebytesAgent.Trojan.Dropper.DDS
PandaGeneric Suspicious
TrendMicro-HouseCallPAK_Xed-21
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.DR.Agent!CafrEvhDur4
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Upatre.0285!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Salgorea-D?

Troj/Salgorea-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment