Virus

Virus:Win32/Sality!Q (file analysis)

Malware Removal

The Virus:Win32/Sality!Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Sality!Q virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Virus:Win32/Sality!Q?


File Info:

crc32: 960C4067
md5: eb4c612e74a23adee759b74b69283845
name: EB4C612E74A23ADEE759B74B69283845.mlw
sha1: 342bd4c7bca0683b6c0b568a0cd7fd0bcb386997
sha256: 8cd5d1d0804e526467e2f7ae0d4154a249231d8fbab6462116fa8b298c1f9a06
sha512: ace74a30fcabf04f0ba06cd170e297efa305738f71fa1c1232935a3fe136bd2d6acf226b875bef449e5f0b8e58617bbdcf60e931336d0cb14216dcb50655cbea
ssdeep: 1536:WH72RUdFXgfdxcEsnDR+uH/W9PpDKFOV/6w8W7bgLztaD9RS6a7T1+sz2DPTKqD:UjKcxxyQGaW7bCtaZQ1haDRWQW6/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus:Win32/Sality!Q also known as:

BkavW32.Sality.PE
K7AntiVirusTrojan ( 001cddbb1 )
Elasticmalicious (high confidence)
DrWebWin32.Sector.30
CynetMalicious (score: 100)
CAT-QuickHealW32.Sality.V
ALYacTrojan.SalityStub.F
CylanceUnsafe
ZillyaVirus.Sality.Win32.23
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 001cddbb1 )
Cybereasonmalicious.e74a23
BaiduWin32.Trojan.Small.a
CyrenW32/SmallTrojan.AO.gen!Eldorado
SymantecW32.Sality.AF
ESET-NOD32Win32/Sality.NDR
APEXMalicious
AvastWin32:Agent-APKD [Trj]
KasperskyTrojan.Win32.Small.cpd
BitDefenderTrojan.SalityStub.F
NANO-AntivirusVirus.Win32.Sality.diawed
ViRobotTrojan.Win32.SalityNHost.99328
MicroWorld-eScanTrojan.SalityStub.F
TencentVirus.Win32.TuTu.Gen.200004
Ad-AwareTrojan.SalityStub.F
SophosMal/Generic-R + ATK/Behav-321
ComodoVirus.Win32.Sality.gen@1egj5j
BitDefenderThetaAI:FileInfector.3B885E080E
VIPRETrojan.Win32.Agent.abc (v)
TrendMicroPE_SALITY.SM-O
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
FireEyeGeneric.mg.eb4c612e74a23ade
EmsisoftTrojan.SalityStub.F (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Small.oace.a
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASVirus.C4
MicrosoftVirus:Win32/Sality.gen!Q
SUPERAntiSpywareTrojan.Agent/Gen-Small
GDataTrojan.SalityStub.F
AhnLab-V3Trojan/Win32.Small.R10023
Acronissuspicious
McAfeeW32/Sality.dr!EB4C612E74A2
MAXmalware (ai score=84)
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Agent
PandaW32/Sality.AA
TrendMicro-HouseCallPE_SALITY.SM-O
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqkQhkUCGalPe7hFWRh7jMe)
YandexTrojan.GenAsa!5Tj45QuXiP0
IkarusTrojan.Win32.Salrenmetie
MaxSecureTrojan.W32.Small.ALJD
FortinetW32/Agent.ABC!tr
AVGWin32:Agent-APKD [Trj]

How to remove Virus:Win32/Sality!Q?

Virus:Win32/Sality!Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment