Malware

What is “Win32/Sality.NBA”?

Malware Removal

The Win32/Sality.NBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Sality.NBA virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to block SafeBoot use by removing registry keys
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.unigas.mn

How to determine Win32/Sality.NBA?


File Info:

crc32: 812490E1
md5: 804996788b5f84af6da71e39d7e5a711
name: baison_print.exe
sha1: ad2586ae9a2ff04641a5c32a207ef46bacac7eff
sha256: e6a87c0823312f8db5913d6a8fd5653bb5d3848ba6d72ab6f4b98cd1b70610a6
sha512: 5bb7537fbef996e4f3e2ba885c23f4eda7792084ddb4b514a986da79b67d9bbc4a0c64290ca5ce9fa9e7e2a3439bc7599a75c095cc929216da3ee8794b924a9a
ssdeep: 24576:qlQgcHSzlEqF+hVcOJnwFy2sz3Mu2WpQ+nm8L7Klj1t:GXl8eONw7GMu2WpQ+m8LYj1t
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004 Indigo Rose Corporation
InternalName: suf70_launch
FileVersion: 7.0.1.0
CompanyName:
PrivateBuild:
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory 7.0
ProductName: Setup Factory 7.0 Runtime
SpecialBuild:
ProductVersion: 7.0.1.0
FileDescription: Setup Application
OriginalFilename: suf70_launch.exe
Translation: 0x0409 0x04e4

Win32/Sality.NBA also known as:

BkavW32.Sality.PE
DrWebWin32.Sector.30
MicroWorld-eScanWin32.Sality.3
CAT-QuickHealW32.Sality.U
McAfeeW32/Sality.gen.z
CylanceUnsafe
VIPREVirus.Win32.Sality.at (v)
K7AntiVirusVirus ( f10001071 )
BitDefenderWin32.Sality.3
K7GWVirus ( f10001071 )
Cybereasonmalicious.88b5f8
TrendMicroPE_SALITY.RL
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
F-ProtW32/Sality.gen2
TotalDefenseWin32/Sality.AA
APEXMalicious
AvastWin32:SaliCode
KasperskyVirus.Win32.Sality.gen
Alibabavirus:Win32/InfectPE.ali2000007
NANO-AntivirusVirus.Win32.Sality.beygb
ViRobotWin32.Sality.Gen.A
AegisLabVirus.Win32.Sality.v!c
RisingVirus.Sality!1.A5BD (CLASSIC)
Ad-AwareWin32.Sality.3
EmsisoftWin32.Sality.3 (B)
ComodoVirus.Win32.Sality.gen@1egj5j
F-SecureMalware.W32/Sality.AT
BaiduWin32.Virus.Sality.gen
ZillyaVirus.Sality.Win32.25
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Sality.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.804996788b5f84af
SophosMal/Sality-D
IkarusVirus.Win32.Sality
CyrenW32/Sality.gen2
JiangminWin32/HLLP.Kuku.poly2
MaxSecureVirus.Sality.BH
AviraW32/Sality.AT
FortinetW32/Sality.BH
Antiy-AVLVirus/Win32.Sality.gen
KingsoftWin32.Sality.lx.368640
Endgamemalicious (high confidence)
ArcabitWin32.Sality.3
ZoneAlarmVirus.Win32.Sality.gen
MicrosoftVirus:Win32/Sality.AT
TACHYONVirus/W32.Sality.D
AhnLab-V3Win32/Kashu.E
Acronissuspicious
VBA32Virus.Win32.Sality.bakc
MAXmalware (ai score=80)
PandaW32/Sality.AA
ZonerTrojan.Win32.Sality.22009
ESET-NOD32Win32/Sality.NBA
TrendMicro-HouseCallPE_SALITY.RL
TencentVirus.Win32.TuTu.Gen.200004
YandexWin32.Sality.BL
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataWin32.Sality.3
AVGWin32:SaliCode
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Virus.Win32.Sality.I

How to remove Win32/Sality.NBA?

Win32/Sality.NBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment