Virus

How to remove “Virus:Win32/Sality.L”?

Malware Removal

The Virus:Win32/Sality.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Sality.L virus can do?

  • Executable code extraction
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Virus:Win32/Sality.L?


File Info:

crc32: 16E12509
md5: 9aa6d512028f3070a8f2e437263b322a
name: 9AA6D512028F3070A8F2E437263B322A.mlw
sha1: 0c5b9f9974921bba9bb63dcf8dfd1a94b043074f
sha256: 0c3a574f9b0fa4b46f112b26d4ef6a0b13c28f2f822972a6dad5fff4c9b5fbe0
sha512: da41612cb2cd6d174fba52e72e803575e931c9e540556206d57b0645f303db2799594b62da52417fbb390a14a693952e94d7d401c51350ed0be267301e24c43b
ssdeep: 1536:jwQVgd54vlVr43oQOdjcJIBkPQ54vTgzQbbE61VAxsx71:sL7q8fUjqkmmdziE61VWsxB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: SHURIKEN 3
FileVersion: 1.00
OriginalFilename: SHURIKEN 3.exe
ProductName: Project1

Virus:Win32/Sality.L also known as:

BkavW32.SalityR.PE
K7AntiVirusVirus ( 0008d6191 )
TotalDefenseWin32/Sality.M
MicroWorld-eScanWorm.VB.NGE
CMCVirus.Win32.Sality!O
CAT-QuickHealW32.Sality.K
ALYacWorm.VB.NGE
CylanceUnsafe
ZillyaWorm.VB.Win32.9
CrowdStrikemalicious_confidence_100% (D)
K7GWVirus ( 0008d6191 )
Cybereasonmalicious.1b8fb7
TrendMicroPE_SALITY.AK
BaiduWin32.Virus.Sality.sg
CyrenW32/Sality.AB
SymantecW32.SillyFDC
ESET-NOD32Win32/Sality.O
ZonerI-Worm.VB.CJ
TheHackerW32/Sality(rp).o
AvastWin32:Mutama [Wrm]
ClamAVWin.Trojan.Sality-1016
GDataWin32.Virus.VB.C
KasperskyVirus.Win32.Sality.o
BitDefenderWorm.VB.NGE
NANO-AntivirusVirus.Win32.Sality.hvgl
ViRobotWin32.Sality.E
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Windows]
TencentTrojan.Win32.FakeFolder.tld
Ad-AwareWorm.VB.NGE
SophosW32/Sality-U
ComodoTrojWare.Win32.Agent.~JH1
F-SecureWorm.VB.NGE
DrWebWin32.HLLW.Brontok
VIPREVirus.Win32.Sality.r (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Sality.dm
EmsisoftWorm.VB.NGE (B)
SentinelOnestatic engine – malicious
F-ProtW32/Sality.AB
Endgamemalicious (high confidence)
AviraW32/Sality.o
Antiy-AVLVirus/Win32.Sality.o
KingsoftWin32.Sality.o.81920
MicrosoftVirus:Win32/Sality.L
JiangminWin32/HLLP.Kuku.d
ArcabitWorm.VB.NGE
AegisLabW32.Sality.liJk
ZoneAlarmVirus.Win32.Sality.o
AhnLab-V3Win32/Sality.G
McAfeeW32/Sality.t
AVwareVirus.Win32.Sality.r (v)
MAXmalware (ai score=88)
VBA32Win32.HLLP.Kuku.307o
PandaW32/Sality.S
TrendMicro-HouseCallPE_SALITY.AK
RisingWorm.VBcode!1.6521 (CLASSIC)
YandexWorm.VB!VLr3R96wN/s
IkarusWorm.Win32.VB
AVGWin32:Mutama [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.38d

How to remove Virus:Win32/Sality.L?

Virus:Win32/Sality.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment