Virus

What is “Virus.Win32.Sality.e”?

Malware Removal

The Virus.Win32.Sality.e is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Sality.e virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus.Win32.Sality.e?


File Info:

name: 30548FDEB937F1C26F16.mlw
path: /opt/CAPEv2/storage/binaries/8bbe96a6f70e5a8cf2f1d37dc5c2ef2d1b2f92ba2f4b263c35b5bd1c9479b255
crc32: 74330C73
md5: 30548fdeb937f1c26f16c06d96608905
sha1: ed0b844fcb7c84815411bad09a47270efaa9c9c8
sha256: 8bbe96a6f70e5a8cf2f1d37dc5c2ef2d1b2f92ba2f4b263c35b5bd1c9479b255
sha512: 5f1c1ffa4e31e28e4667f559b83c48c955547941941e6256e3f174e03e47d57815d28eead4336910993db4ce49e7e6ee433ae8fabba92b794511eb60e07bcbe7
ssdeep: 6144:DYu8n5Qw0tneDA/sqhleIc0HftDrkYY1hj63hgDonsogCh6NEpAFqYQu:DYu85bM3npxYfj63hgD1ZiH+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128A4190277E99135F6F31B31AEB592614A7ABC729D35C20F23D41A0D0DB0A90EA75B73
sha3_384: 2fd1ea46acb3b85cb97bda4563e20fc37a0d803e068c8c5de0c3179c73d8e30102c90e10472b16462124194f69797a7f
ep_bytes: b96c634000b800800000e808290000e8
timestamp: 2003-01-15 17:50:08

Version Info:

0: [No Data]

Virus.Win32.Sality.e also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Lamer.lLv3
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61636945
FireEyeGeneric.mg.30548fdeb937f1c2
CAT-QuickHealW32.Sality.E3
McAfeeW32/Sality.i.gen
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Save.a
BitDefenderTrojan.GenericKD.61636945
Cybereasonmalicious.fcb7c8
CyrenW32/ABRisk.DVVL-7635
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Evo-gen [Trj]
KasperskyVirus.Win32.Sality.e
AlibabaVirus:Win32/Sality.cb0c08bf
RisingWin32.Sality.e (CLASSIC)
Ad-AwareTrojan.GenericKD.61636945
EmsisoftTrojan.GenericKD.61636945 (B)
DrWebWin32.HLLP.Sector.17368
TrendMicroTROJ_GEN.R002C0PHV22
McAfee-GW-EditionBehavesLike.Win32.Sality.gh
Trapminemalicious.high.ml.score
SophosW32/Sality-F
SentinelOneStatic AI – Suspicious PE
JiangminWin32/Sality.d
AviraTR/Patched.Ren.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.61636945
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34606.DmZ@aKq2d!p
ALYacTrojan.GenericKD.61636945
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PHV22
TencentVirus.Win32.Sality.tt
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Virus.Win32.Sality.e?

Virus.Win32.Sality.e removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment