Virus

What is “Virus.Sality.16109”?

Malware Removal

The Virus.Sality.16109 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Sality.16109 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Virus.Sality.16109?


File Info:

name: ABFA37AACF6B8BB8D7E3.mlw
path: /opt/CAPEv2/storage/binaries/1c9e9c65f8c4615ff51c8f198306b99e91d5917af19820684369c480cacc8115
crc32: 62A662E0
md5: abfa37aacf6b8bb8d7e3084cd0908156
sha1: db6a59634da089c7148c5fae885e457d80561296
sha256: 1c9e9c65f8c4615ff51c8f198306b99e91d5917af19820684369c480cacc8115
sha512: 5fab938932e6a6e00e15bea9307aad6f625c76f935c31fc7a35b89c9e882c13ce2e1b27b38db506704a3d7e496b9831e591122e976b7593fdf94b4eb879f07a4
ssdeep: 1536:NhrkTzNQydlv/ikWuo1exDSIPEYOTnXSe08hhPHwtWop6ea5mMhm3GdGab:N5UDndDSIMYOTX90+5HwYRf5mY0GYU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161248F2BB081E4F6DC8309F11E9276E3E274B9321A384215FF96161EF6795F1D12742E
sha3_384: e11b6db9db1b667ba7d03109d2e9cf7cddcf81f74423e94d4383a63c0dc4b724bbc62d7685e0e2070337cad60a3f0a3a
ep_bytes: b99cb04000b800800000e8b72a0000e8
timestamp: 2004-02-15 21:27:58

Version Info:

0: [No Data]

Virus.Sality.16109 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Sality.H
FireEyeGeneric.mg.abfa37aacf6b8bb8
ALYacDropped:Win32.Sality.H
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.16205
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0040f8141 )
K7GWVirus ( 0040f8141 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin32.Trojan.Sality.m
CyrenW32/Sality.OCXO-0174
SymantecW32.Sality
ESET-NOD32Win32/Sality.X
APEXMalicious
KasperskyVirus.Win32.Sality.x
BitDefenderDropped:Win32.Sality.H
NANO-AntivirusVirus.Win32.Sality.ryed
AvastWin32:Sality-AV
TencentVirus.Win32.KuKu.tt
Ad-AwareDropped:Win32.Sality.H
SophosMal/Generic-S
ComodoWin32.Sality.X@d1pc
DrWebWin32.HLLP.Sector.28318
TrendMicroTROJ_SPNR.0BJC11
McAfee-GW-EditionBehavesLike.Win32.Sality.dz
EmsisoftDropped:Win32.Sality.H (B)
SentinelOneStatic AI – Malicious PE
GDataDropped:Win32.Sality.H
AviraW32/Sality.g
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeW32/Sality.i.gen
MAXmalware (ai score=85)
VBA32Virus.Sality.16109
MalwarebytesMalware.AI.2079763335
TrendMicro-HouseCallTROJ_SPNR.0BJC11
RisingBackdoor.KUKU!1.A155 (RDMK:cmRtazoi4gzeCyZUEc9Ijt5bKyua)
YandexTrojan.GenAsa!trUTzOkYLyE
IkarusVirus.Win32.Sality
eGambitUnsafe.AI_Score_97%
FortinetW32/Sality.I!tr
BitDefenderThetaGen:NN.ZexaF.34160.nmW@aikte2lc
AVGWin32:Sality-AV
Cybereasonmalicious.acf6b8
PandaTrj/Genetic.gen
MaxSecureVirus.W32.Sality.X

How to remove Virus.Sality.16109?

Virus.Sality.16109 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment