Malware

Win32.Sality.OG malicious file

Malware Removal

The Win32.Sality.OG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Sality.OG virus can do?

  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32.Sality.OG?


File Info:

name: AC2E79A3044A06C6D1F1.mlw
path: /opt/CAPEv2/storage/binaries/ff0b1b3f57ebe81484ea580a26bd881682c1bdab54cdf1dea4d7a6b8e17b58a0
crc32: B87E2774
md5: ac2e79a3044a06c6d1f123f73a1f392d
sha1: 5395cb9d5c1f169f0118fb7f7101e693c5380ba9
sha256: ff0b1b3f57ebe81484ea580a26bd881682c1bdab54cdf1dea4d7a6b8e17b58a0
sha512: 5a2c112ed61e80a0ba4a8c4ae7f48d163d7e8e3f45dc842123de32f87f3d913c3d2df4fee9aa01adfabfbdc19fb12795f4edbfe0110111ee237e3dad20164df8
ssdeep: 6144:/C28HTszv0kVi7aA/mpu1JpDXEpXsGKLu8NE04SerNuAS2n:pOi0kg7reg9DUtmxF7V2n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B964BF3634E08473F443003026B97FB6F6FAFE3217715887D7586F4A6E76A96C226216
sha3_384: 34a32a657c5bae5518c5414a3fea5d49061b4008115800f49a7814e1f0daf85c319e5a903452dfe8f1dff21b3c45666d
ep_bytes: 60510faff18d2dd34ae5145e15b5a4d7
timestamp: 2003-04-10 21:51:10

Version Info:

Comments:
CompanyName: Adobe Systems Incorporated
FileDescription: Setup Launcher
FileVersion: 7.0.5
InternalName: setup.exe
OriginalFilename: setup.exe
LegalCopyright: Copyright (C) 2003 InstallShield Software Corp.
ProductName: Adobe Reader 7.0.5 - Russian
ProductVersion: 7.0.5
Translation: 0x0419 0x04e4

Win32.Sality.OG also known as:

BkavW32.Sality.PE
LionicVirus.Win32.Generic.n!c
DrWebWin32.Sector.17
MicroWorld-eScanWin32.Sality.OG
FireEyeGeneric.mg.ac2e79a3044a06c6
CAT-QuickHealW32.Sality.R
SkyhighW32/Sality.gen.z
McAfeeW32/Sality.gen.z
Cylanceunsafe
ZillyaVirus.Sality.Win32.15
SangforVirus.Win32.Sality.NAU
K7AntiVirusVirus ( f10001021 )
AlibabaVirus:Win32/Sality.20fb39a2
K7GWVirus ( f10001021 )
Cybereasonmalicious.d5c1f1
BitDefenderThetaAI:FileInfector.2A9374620F
VirITWin32.Sality.AA
SymantecW32.Sality.AE
Elasticmalicious (high confidence)
ESET-NOD32Win32/Sality.NAU
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Sality.sil
BitDefenderWin32.Sality.OG
NANO-AntivirusVirus.Win32.Sality.gcen
AvastWin32:Kukacka [Inf]
TencentVirus.Win32.TuTu.A.200000
EmsisoftWin32.Sality.OG (B)
F-SecureMalware.W32/Sality.Y
BaiduWin32.Virus.Sality.b
VIPREWin32.Sality.OG
TrendMicroPE_SALITY.JER
Trapminesuspicious.low.ml.score
SophosW32/Sality-AM
SentinelOneStatic AI – Suspicious PE
GDataWin32.Sality.OG
JiangminWin32/HLLP.Kuku.poly
GoogleDetected
AviraW32/Sality.Y
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Sality.gen
KingsoftWin32.Sality.ab.173464
XcitiumVirus.Win32.Sality.gen@1egj5j
ArcabitWin32.Sality.OG
ViRobotWin32.Sality.Gen.A
ZoneAlarmVirus.Win32.Sality.sil
MicrosoftVirus:Win32/Sality.AM
VaristW32/Sality.AK
AhnLab-V3Win32/Kashu.B
VBA32Virus.Win32.Sality.baka
ALYacWin32.Sality.OG
TACHYONVirus/W32.Sality
PandaW32/Sality.AK
TrendMicro-HouseCallPE_SALITY.JER
RisingVirus.Sality!1.A5BD (CLASSIC)
YandexWin32.Sality.AP.Gen
IkarusVirus.Win32.Sality
MaxSecureVirus.Sality.AA
FortinetW32/Sality.AA
AVGWin32:Kukacka [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Sality.OG?

Win32.Sality.OG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment