Trojan

Trojan:Win32/Salgorea.C!MTB removal tips

Malware Removal

The Trojan:Win32/Salgorea.C!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Salgorea.C!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Salgorea.C!MTB?


File Info:

name: 7461CA6FA618D85D6F45.mlw
path: /opt/CAPEv2/storage/binaries/5a73d96c0f20a38d1fb50dc7908cd35f5c129967fbcaa929a70649e3a878c808
crc32: 70511BC0
md5: 7461ca6fa618d85d6f457cdf5308ef04
sha1: 93d870656a531ae5057343e97d0131ae0dab3732
sha256: 5a73d96c0f20a38d1fb50dc7908cd35f5c129967fbcaa929a70649e3a878c808
sha512: 1504cfd5eb29ae2f26dde060c980daa06e8bbc117dc791597feacc9de6e51c7eba6482b1793c2c302c1f442d97d6df718761ca080860b30b36bba38ee9727ef5
ssdeep: 24576:yYHI93Rq//AdOTP/Kin0LT/gx3TQku8zqng2YMYtzXuEqK3K8l:yYHI93Rq/4u3KqEjgx3TQku8kg2YMYRr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E205C02FB2411373C19202722A0FD5D6BB3E6939136A89D374A8912D2773F6493FB395
sha3_384: b8bb798ee946c3ca47e955fb396503a4822a0348011f4e4e00801c077c792bd9e9c712e13980a673b971216171d9455c
ep_bytes: e873370000e989feffff8bff558bec5d
timestamp: 1991-11-03 23:44:31

Version Info:

Comments: GIF Image
FileDescription: GIF Image
FileVersion: 6.1.7601.17514
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Trojan:Win32/Salgorea.C!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.34530
MicroWorld-eScanTrojan.GenericKDZ.96285
ClamAVWin.Malware.Ulise-9768992-0
CAT-QuickHealTrojan.GenericRI.S30116379
McAfeeGenericRXBE-HL!7461CA6FA618
MalwarebytesAgent.Trojan.Dropper.DDS
ZillyaDropper.Agent.Win32.258549
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005720591 )
K7GWTrojan ( 005720591 )
Cybereasonmalicious.fa618d
BitDefenderThetaGen:NN.ZexaF.36196.ZC3@a4K8Icgi
CyrenW32/Trojan.PQAW-0235
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RHG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.96285
NANO-AntivirusTrojan.Win32.Agent.emthez
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10b096d4
TACHYONBackdoor/W32.Agent.839610
EmsisoftTrojan.GenericKDZ.96285 (B)
VIPRETrojan.GenericKDZ.96285
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7461ca6fa618d85d
SophosTroj/Agent-BAII
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.96285
JiangminTrojan.Generic.aumts
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Salgorea.RPR@7tcxjx
ArcabitTrojan.Generic.D1781D
ZoneAlarmHEUR:Backdoor.Win32.Generic
MicrosoftTrojan:Win32/Salgorea.C!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Salgorea.R373812
VBA32BScope.TrojanDropper.Agent
ALYacTrojan.GenericKDZ.96285
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDropper.Agent!8.2F (TFE:5:7Ood33l4AvK)
IkarusTrojan.Win32.Salgorea
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AP.A8FFC!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Salgorea.C!MTB?

Trojan:Win32/Salgorea.C!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment