Virus

How to remove “Virus:Win32/Sality.AM”?

Malware Removal

The Virus:Win32/Sality.AM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Sality.AM virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win32/Sality.AM?


File Info:

name: 58940E185BECD9E00D59.mlw
path: /opt/CAPEv2/storage/binaries/87768ddd3f7c42a4a65f3c5169097087d3687437635d625a19ac44f9e847d3bd
crc32: D427496A
md5: 58940e185becd9e00d594c0dabbe20fb
sha1: 93e9863d23c3508164537320d4a68ab5488d89b6
sha256: 87768ddd3f7c42a4a65f3c5169097087d3687437635d625a19ac44f9e847d3bd
sha512: 61d92d2eaedf9fe3525b9dcc436ee4355a4c41525e360c3a0b9a54e625bf5a5789c69e2798e0cef0c7b4473326fd94e033b44dadc4a7840cab6eb97e8b7ccf56
ssdeep: 6144:8Pqs3al2lZDp0X+u848/Zjz6PFVdBIgDTpKyTPZDjbLl0CtC0lVZ6ups/C/2rSNt:C4auY5GpXTHtIO5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12494D01AF6953A11F4BA24B45EC8BE3E4A59ED306B4548C77780CFE964201E7243DACF
sha3_384: bede2944ea2dc9e90077d9137295d51cd56a1d3d3065264f89abccc88faf64bb0d4066d1dbb8f074fe99bf8f3a5a8c72
ep_bytes: 6003c53ac60fbbf7eb01ab8bc689ee1c
timestamp: 2016-07-16 01:36:48

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Notepad
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: Notepad
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: NOTEPAD.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.14393.0
Translation: 0x0409 0x04b0

Virus:Win32/Sality.AM also known as:

BkavW32.SalityVD.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Sality.OG
FireEyeGeneric.mg.58940e185becd9e0
CAT-QuickHealW32.Sality.R
ALYacWin32.Sality.OG
MalwarebytesMalware.Heuristic.1001
ZillyaVirus.Sality.Win32.15
SangforVirus_Suspicious.Win32.Sality.gen
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( f10001011 )
K7AntiVirusVirus ( f10001011 )
BitDefenderThetaAI:FileInfector.2A9374620F
VirITWin32.Sality.AA
CyrenW32/Sality.AK
SymantecW32.Sality.AE
ESET-NOD32Win32/Sality.NAR
BaiduWin32.Virus.Sality.b
APEXMalicious
ClamAVWin.Trojan.Sality-1038
KasperskyVirus.Win32.Sality.sil
BitDefenderWin32.Sality.OG
NANO-AntivirusVirus.Win32.Sality.gcen
AvastWin32:Kukacka [Inf]
RisingWin32.KUKU.a (CLASSIC)
EmsisoftWin32.Sality.OG (B)
ComodoVirus.Win32.Sality.gen@1egj5j
F-SecureMalware.W32/Sality.Y
DrWebWin32.Sector.17
VIPREVirus.Win32.Sality.ah (v)
TrendMicroPE_SALITY.EN-1
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gm
SophosML/PE-A + W32/Sality-AM
IkarusVirus.Win32.Sality
JiangminWin32/HLLP.Kuku.poly
AviraW32/Sality.Y
Antiy-AVLVirus/Win32.Sality.gen
MicrosoftVirus:Win32/Sality.AM
ViRobotWin32.Sality.Gen.A
ZoneAlarmVirus.Win32.Sality.sil
GDataWin32.Sality.OG
CynetMalicious (score: 100)
AhnLab-V3Win32/Kashu.B
McAfeeW32/Sality.gen.z
MAXmalware (ai score=81)
VBA32Virus.Win32.Sality.kaka
CylanceUnsafe
TrendMicro-HouseCallPE_SALITY.EN-1
TencentVirus.Win32.TuTu.A.200000
YandexWin32.Sality.AO.Gen
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Sality.AA
FortinetW32/Sality.AA
AVGWin32:Kukacka [Inf]
Cybereasonmalicious.85becd
PandaW32/Sality.AK

How to remove Virus:Win32/Sality.AM?

Virus:Win32/Sality.AM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment