Trojan

Trojan:Win32/Salgorea!pz removal guide

Malware Removal

The Trojan:Win32/Salgorea!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Salgorea!pz virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Salgorea!pz?


File Info:

name: 759588BFDE61D43C6B79.mlw
path: /opt/CAPEv2/storage/binaries/69c1581ac67312fb640b70635f0e15fa2f7fd84265972a5fc0284640183cde5b
crc32: 95C12C62
md5: 759588bfde61d43c6b790581a20f94bc
sha1: 931ab1303f70d9bedd358e713499bcae8ffec0a5
sha256: 69c1581ac67312fb640b70635f0e15fa2f7fd84265972a5fc0284640183cde5b
sha512: 88211475855d9cb6ed0d6233ac048e39d6b7161a0b27f1e4ec7f1e9a6344ab9661728a7fa4ad60eadbbf0bb359ac820a0b04d63695ce4496663d1fff52b29560
ssdeep: 24576:pUIcfl8Fl531HPwQBC+gKySBvWNuIiSVsrKMo3v9xDgjT:pWs1HPwKySBfIiSxx3vP0jT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6451264AA9082F7C54A40711B1ADBFA6D353D3A46219EC732ED3A2D7D702C17B72327
sha3_384: c75027b72bf8b3b58b6601345579d7b91d5b37817ab514d93e0faa5f3bda0fd6677e17f6b482a2cf05cc5ccd487b02de
ep_bytes: e8fe350000e989feffff3b0d4c3d5100
timestamp: 2009-01-06 02:30:31

Version Info:

Comments: JPEG Image
FileDescription: JPEG Image
FileVersion: 6.1.7601.17514
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Trojan:Win32/Salgorea!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94906
ClamAVWin.Malware.Ulise-9768992-0
FireEyeGeneric.mg.759588bfde61d43c
CAT-QuickHealTrojan.GenericIH.S21252934
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXDF-ES!759588BFDE61
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Generic.Win32.1008
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005749851 )
K7GWTrojan ( 005749851 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D172BA
BitDefenderThetaAI:Packer.EE050F961F
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RJF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderTrojan.GenericKDZ.94906
NANO-AntivirusTrojan.Win32.Jaiko.fidrfv
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:DropperX-gen [Drp]
EmsisoftTrojan.GenericKDZ.94906 (B)
F-SecureHeuristic.HEUR/AGEN.1313003
DrWebTrojan.MulDrop6.18204
VIPRETrojan.GenericKDZ.94906
TrendMicroTrojan.Win32.SALGOREA.SMLV
SophosTroj/Agent-BFWM
IkarusTrojan.Win32.Salgorea
JiangminBackdoor.Generic.atdm
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1313003
Antiy-AVLTrojan/Win32.Salgorea.c
XcitiumTrojWare.Win32.Salgorea.RPR@7tcxjx
MicrosoftTrojan:Win32/Salgorea!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.94906
VaristW32/Salgorea.AD.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R621821
VBA32BScope.Trojan.MulDrop
ALYacTrojan.GenericKDZ.94906
TACHYONBackdoor/W32.Agent.1213440.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SALGOREA.SMLV
RisingTrojan.Agent!1.B332 (CLASSIC)
YandexTrojan.GenAsa!9n/WI8CpUGY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RJF!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.03f70d
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Salgorea!pz?

Trojan:Win32/Salgorea!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment