Virus

Should I remove “Virus.Win32.Sality.bh”?

Malware Removal

The Virus.Win32.Sality.bh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Sality.bh virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid

How to determine Virus.Win32.Sality.bh?


File Info:

name: AC5B220495392C3E6FC7.mlw
path: /opt/CAPEv2/storage/binaries/5f00208f861cf1fedfdd39d90fdc84e75cdd53a3b9c84ca0fa7bfdce66e2090f
crc32: D66A1931
md5: ac5b220495392c3e6fc75a31fd26bb20
sha1: bdfb5eb5705e8cb3d2e248fa3078afd1868960da
sha256: 5f00208f861cf1fedfdd39d90fdc84e75cdd53a3b9c84ca0fa7bfdce66e2090f
sha512: fe76888bf63721fa171186f60fb4e2d8b90f6e8c1150ab57c7fa95bf927b5b6f9cf7d4cb80131e7086300c168d31ae88b1b7991352c8796cb2a9800add25572b
ssdeep: 24:eH1GSAM63EX1R9/Ebveoqq356fPVKPBJ:yS3mBEre9256ftKPB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B35558317A9ACB9C28C217A15C7C406B8BE580507F286B71FA0107DA43636A39B5E11
sha3_384: 2ea996c6399c2f3c986e8685aad11d060aaa70e9272a3d9bdd617b3adbcdf346261d964f2821248ada8d91e97c75b54a
ep_bytes: e800000000580f6ee00f7ee681c67502
timestamp: 2010-11-05 00:25:00

Version Info:

0: [No Data]

Virus.Win32.Sality.bh also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ac5b220495392c3e
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePWS-Zbot.gen.yh
CylanceUnsafe
ZillyaTrojan.Sality.Win32.99
K7AntiVirusTrojan ( 001cddbb1 )
K7GWTrojan ( 001cddbb1 )
CrowdStrikewin/malicious_confidence_80% (W)
BaiduWin32.Trojan.Small.a
CyrenW32/Sality.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrashBytes.I potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Small-5420
KasperskyVirus.Win32.Sality.bh
BitDefenderTrojan.SalityStub.F
MicroWorld-eScanTrojan.SalityStub.F
AvastWin32:Agent-APKD [Trj]
EmsisoftTrojan.SalityStub.F (B)
ComodoTrojWare.Win32.Salrenmetie.A@4w2swt
DrWebmodification of Win32.Sector.23
VIPRETrojan.Win32.Agent.abc (v)
TrendMicroTSPY_AGENT_CA082D2E.TOMC
McAfee-GW-EditionPWS-Zbot.gen.yh
SophosML/PE-A + Troj/SalLoad-C
IkarusTrojan.Win32.Salrenmetie
GDataTrojan.SalityStub.F
JiangminTrojan/Small.oace.a
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.3762
ArcabitTrojan.SalityStub.F
ViRobotTrojan.Win32.SalityNHost.99328
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Small.R10023
Acronissuspicious
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
MAXmalware (ai score=82)
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTSPY_AGENT_CA082D2E.TOMC
RisingTrojan.Win32.Fednu.cua (CLASSIC)
YandexTrojan.GenAsa!5Tj45QuXiP0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Small.ALJD
FortinetW32/Agent.ABC!tr
AVGWin32:Agent-APKD [Trj]
Cybereasonmalicious.495392

How to remove Virus.Win32.Sality.bh?

Virus.Win32.Sality.bh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment