Malware

Win32/Sality.NEZ removal

Malware Removal

The Win32/Sality.NEZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Sality.NEZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Catalan
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Ramnit malware family
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Sality.NEZ?


File Info:

name: 23483985885F5D9F9770.mlw
path: /opt/CAPEv2/storage/binaries/8a3bf35f55f18c4e0abaa929025398f5bc9629aa7c0c7d310283670b20ce138f
crc32: 2F96687C
md5: 23483985885f5d9f9770f7cdeeff9470
sha1: f982d38fdc1d5baa1959165ab527f62d93078347
sha256: 8a3bf35f55f18c4e0abaa929025398f5bc9629aa7c0c7d310283670b20ce138f
sha512: 3e0f8655f5cf794535c5b7caa04ab185247cfad6402420d39a671157d60fb2ccb41725a1eb23152a038212cad030d369c3e4f914fea6adc9b4462c8436c55552
ssdeep: 3072:jR2xn3k0CdM1vabyzJYWqQa2/aRmpTt+N6CLwDNKQjScdSC6UnBtoD3:jR2J0LS6VwkmpTXYQjN0WPob
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D940249B53252DAEAEDA8348431FBC05D39FC2904B3C873389C11DAAB36DC5925677D
sha3_384: 74f59ab70861b5be9a435cf4aaa3b54c7873e756fe1e010394f9e5c3d96c54f5905bca167470bd26e170e66bf298e78f
ep_bytes: 60414bd2ccf2b9629734fab9a79af89e
timestamp: 2001-06-13 01:28:07

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Macromedia Flash Player 7.0 r19
FileVersion: 7,0,19,0
InternalName: Macromedia Flash Player 7.0
LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: SAFlashPlayer.exe
ProductName: Shockwave Flash
ProductVersion: 7,0,19,0
Translation: 0x0409 0x04b0

Win32/Sality.NEZ also known as:

BkavW32.Sality.PE
LionicTrojan.Win32.Generic.lIHt
MicroWorld-eScanWin32.Sality.3
FireEyeGeneric.mg.23483985885f5d9f
CAT-QuickHealW32.Sality.U
SkyhighBehavesLike.Win32.ZBot.gz
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Sality.3
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusVirus ( f10001021 )
BitDefenderWin32.Sality.3
K7GWVirus ( f10001021 )
Cybereasonmalicious.fdc1d5
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
VirITTrojan.Win32.Generic.SUG
SymantecPacked.Protexor!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Sality.NEZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Sality.sil
AlibabaVirus:Win32/Sality.a313952e
NANO-AntivirusVirus.Win32.Sality.yusp
ViRobotWorm.Win32.A.Net-Koobface.126464
RisingVirus.Sality!1.A5BD (CLASSIC)
SophosMal/Sality-E
BaiduWin32.Virus.Sality.gen
F-SecureMalware.W32/Sality.AT
DrWebTrojan.Siggen2.9448
Trapminemalicious.high.ml.score
EmsisoftWin32.Sality.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/HLLP.Kuku.aa
WebrootW32.Virus.AT
VaristW32/Sality.gen2
AviraW32/Sality.AT
Antiy-AVLVirus/Win32.Ramnit
KingsoftWin32.Sality.ab.173464
MicrosoftVirus:Win32/Sality.AT
XcitiumVirus.Win32.Sality.gen@1egj5j
ArcabitWin32.Sality.3
SUPERAntiSpywareTrojan.Agent/Gen-Pune
ZoneAlarmVirus.Win32.Sality.sil
GDataWin32.Sality.3
GoogleDetected
AhnLab-V3Trojan/Win32.Krap.R20076
VBA32Virus.Win32.Sality.bakb
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Pck_Pretorx.A
TencentTrojan.Win32.Koobface.udb
YandexTrojan.Inject!Tlr7FralH0U
IkarusVirus.Win32.Ramnit
MaxSecureVirus.Sality.BH
FortinetW32/Generic.AC.9B6!tr
AVGWin32:Kukacka [Inf]
AvastWin32:Kukacka [Inf]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Sality.NEZ?

Win32/Sality.NEZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment