Virus

Virus:Win32/Sality.J information

Malware Removal

The Virus:Win32/Sality.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Sality.J virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

How to determine Virus:Win32/Sality.J?


File Info:

name: CD6C4D81C820DA7596E0.mlw
path: /opt/CAPEv2/storage/binaries/f5d9815bad7799758db7a179d1bd516bb2d3c676e830ede730372d4e71feef6b
crc32: D3B4E399
md5: cd6c4d81c820da7596e0021e49c64943
sha1: 7bc1e2b0c318463431e0dad4e74438292cf53f15
sha256: f5d9815bad7799758db7a179d1bd516bb2d3c676e830ede730372d4e71feef6b
sha512: f2addabbd042aa74167054f8cbc1a71b4531dba922ce54d79a041b3d4d235667c498e5c85bb78d48303445953f4835a3fa383ee03a79e29f04459b476c5aeb66
ssdeep: 6144:Nbep5Qw0tneDA/sqhleIc0HftDrkYY1hj63hgDonsogCh6NEpAFE2aY3:labM3npxYfj63hgD1Zid2aY3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FB41902B7F99135F6F31B31AEB592515A7ABC629D35C20F23C4260D0DB0A90EA75B73
sha3_384: 92d0d4feb396f1e5052ea2d3072dff867cd077f93ed512307b3cb05b3dd1280ef1589c7d65081db2c005c3bb9e1367e9
ep_bytes: 60e8000000005883e83d508db800f0fd
timestamp: 2004-02-09 19:06:07

Version Info:

0: [No Data]

Virus:Win32/Sality.J also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Sality.H
FireEyeGeneric.mg.cd6c4d81c820da75
CAT-QuickHealW32.Sality.I
ALYacWin32.Sality.H
CylanceUnsafe
K7AntiVirusVirus ( 0040f8141 )
K7GWVirus ( 0040f8141 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITWin32.Sality.F
CyrenW32/Sality.WBPW-4168
SymantecW32.Sality
tehtrisGeneric.Malware
ESET-NOD32Win32/Sality.I
BaiduWin32.Trojan.Sality.i
TrendMicro-HouseCallPE_SALITY.H
ClamAVWin.Trojan.Sality-1025
KasperskyVirus.Win32.Sality.i
BitDefenderWin32.Sality.H
NANO-AntivirusTrojan.Win32.Sality.bottkc
APEXMalicious
TencentVirus.Win32.KuKu.tt
Ad-AwareWin32.Sality.H
EmsisoftWin32.Sality.H (B)
ComodoWin32.Sality.I@1fa1
DrWebWin32.HLLP.Sector.28222
VIPREWin32.Sality.H
TrendMicroPE_SALITY.H
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gh
Trapminesuspicious.low.ml.score
SophosML/PE-A + W32/Sality-H
IkarusVirus.Win32.Ipamor
GDataWin32.Sality.H
JiangminVirus.Sality.d
AviraW32/Sality.g
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.1018
MicrosoftVirus:Win32/Sality.J
CynetMalicious (score: 100)
AhnLab-V3Virus/Win32.Sality.R174168
McAfeeW32/Sality.i.gen
VBA32Virus.Sality.1015
MalwarebytesMalware.AI.4111761169
AvastWin32:Sality
ZonerProbably Heur.ExeHeaderL
RisingBackdoor.Kuku!1.A155 (CLASSIC)
YandexTrojan.GenAsa!dUDSOmJHLTo
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Sality.I
FortinetW32/Sality.I
AVGWin32:Sality
Cybereasonmalicious.1c820d

How to remove Virus:Win32/Sality.J?

Virus:Win32/Sality.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment