Malware

Should I remove “Win32/Salgorea.AQ”?

Malware Removal

The Win32/Salgorea.AQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Salgorea.AQ virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Salgorea.AQ?


File Info:

crc32: 2AD86A54
md5: 3fade768e4a9d3ddf78fee0790571478
name: 3FADE768E4A9D3DDF78FEE0790571478.mlw
sha1: 090825f514eb10a038e01c63312d107bec009bbe
sha256: b78c357f0747398f44a4eee1140c0b10db639911bdee88d1e23a99b007bd3dea
sha512: 2287790baa994cf35cb48a2d46e5e867556fcb74f7d61728d058bcbc51b126e92eb31805221adea65797771729a5f8eb74396b490731d34f2d966333206b41b8
ssdeep: 24576:N2oo60HPdt+1CRiY2eOBvcj3u10dKNq91KTm5ClOFPK46WNZ30xQeiqzguMO0paH:Qoa1taC070dpL5Cl8i8YkdxZ4ldp3WqH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Salgorea.AQ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.43397
MicroWorld-eScanTrojan.GenericKD.44375344
FireEyeGeneric.mg.3fade768e4a9d3dd
ALYacTrojan.GenericKD.44375344
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004fdf0a1 )
BitDefenderTrojan.GenericKD.44375344
K7GWTrojan ( 004fdf0a1 )
Cybereasonmalicious.8e4a9d
BitDefenderThetaAI:Packer.DFB6820820
CyrenW32/S-8e0acc48!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zusy-6291552-0
KasperskyBackdoor.Win32.Finfish.ow
NANO-AntivirusTrojan.Win32.Salgorea.ellsnj
RisingBackdoor.Finfish!8.192 (TFE:5:xsaFnaNFiqD)
Ad-AwareTrojan.GenericKD.44375344
SophosML/PE-A + Mal/Salgorea-A
ComodoTrojWare.Win32.Salgorea.AQ@73zvwa
F-SecureHeuristic.HEUR/AGEN.1117294
ZillyaTrojan.Black.Win32.47443
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Malicious PE – Downloader
EmsisoftTrojan.GenericKD.44375344 (B)
IkarusTrojan.Win32.Skeeyah
JiangminBackdoor.Finfish.y
AviraHEUR/AGEN.1117294
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Generic.D2A51D30
ZoneAlarmBackdoor.Win32.Finfish.ow
GDataTrojan.GenericKD.44375344
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1664134
Acronissuspicious
McAfeeGenericRXAO-HZ!3FADE768E4A9
MAXmalware (ai score=85)
VBA32Backdoor.Finfish
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Salgorea.AQ
TencentMalware.Win32.Gencirc.10b2f8c3
YandexTrojan.GenAsa!Vl/tO0Uk9tE
TACHYONBackdoor/W32.Finfish.1958400
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.39E2FE!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.0510.Malware.Gen

How to remove Win32/Salgorea.AQ?

Win32/Salgorea.AQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment