Malware

Win32/Sality.NDH removal instruction

Malware Removal

The Win32/Sality.NDH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Sality.NDH virus can do?

  • Unconventionial language used in binary resources: Portuguese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Sality.NDH?


File Info:

name: 08911A5591A51329D6F3.mlw
path: /opt/CAPEv2/storage/binaries/1e736cc4d3f6dec35e98344472904ba90adb6ea653429d9b6ef9774ead33f54c
crc32: 1111CA15
md5: 08911a5591a51329d6f357a78532eb39
sha1: 03597bb35b3f4f8e3c5014ac5d83afe8879e25b6
sha256: 1e736cc4d3f6dec35e98344472904ba90adb6ea653429d9b6ef9774ead33f54c
sha512: 20896755508a4c6fdb1f13f75f0aec732feb606d7ff986d4d1085f10c63f5e5e8107ca205aee6be53ad61df3a66d2de10527945109de76c8cfb136801e3eb8bc
ssdeep: 384:VYGGrdDSV//arDomqPKsBaQkgUr+5NaDE045H40M0M0M0M0IT:2GGJDSVHlTK0DYMgAZLLLLI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9629F7741AC1CB7FF1C007F5A8B81C526D570B41F46A2A569FB909A4F253A52970F83
sha3_384: 8a73ff45bbadbf8d89942fecc00e1044c784eab5f5aeb9be6ed0d6ba33d810f2eeae1e693c1b0394a4c55f63e7375401
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Sality.NDH also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.labP
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.93996
ClamAVWin.Dropper.Genericrxtl-9984702-0
FireEyeGeneric.mg.08911a5591a51329
McAfeeGenericRXTL-LJ!08911A5591A5
Cylanceunsafe
ZillyaBackdoor.Poison.Win32.98872
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
AlibabaTrojan:Win32/Grandoreiro.5161e094
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.35b3f4
BitDefenderThetaGen:NN.ZexaF.36250.amW@aOx903iG
CyrenW32/Kryptik.ISB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Sality.NDH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderTrojan.GenericKDZ.93996
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.xhae
EmsisoftTrojan.GenericKDZ.93996 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKDZ.93996
TrendMicroTROJ_GEN.R002C0DCA23
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminemalicious.high.ml.score
SophosMal/ExeSax-A
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.93996
JiangminTrojan/Generic.bghcg
AviraTR/Dropper.Gen
Antiy-AVLGrayWare/Win32.Krap.cku
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Generic.D16F2C
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
GoogleDetected
AhnLab-V3Trojan/Win.LJ.R535457
VBA32Malware-Cryptor.General.3
ALYacTrojan.GenericKDZ.93996
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DCA23
RisingTrojan.Generic@AI.100 (RDML:zqTDCk4tkc24JUSI8460dw)
IkarusVirus.Win32.VB.FEW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Krap.CKU!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Sality.NDH?

Win32/Sality.NDH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment