Malware

Win32.Sality.OG removal tips

Malware Removal

The Win32.Sality.OG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Sality.OG virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32.Sality.OG?


File Info:

name: 0B6FECE0EE40DD2F8731.mlw
path: /opt/CAPEv2/storage/binaries/410aff5db5193f7cd8c1a1e4ec6eecdab90fc91f0baef0a958760c84ce5a0d42
crc32: A74B679A
md5: 0b6fece0ee40dd2f87317f92d165833d
sha1: 6e77756bb38e1628a8c9477604ced2b46e3dd035
sha256: 410aff5db5193f7cd8c1a1e4ec6eecdab90fc91f0baef0a958760c84ce5a0d42
sha512: cdf702d556ace85e15a0f4f9d279ac3b55ae850b6e09b468305242f1784a63601491f2d3f4a8f3ec1c04cb28cf6541c12126e52969245115184463b80a6f600b
ssdeep: 6144:Dq7G5EedkozhoMwScQKmZCeQ3TQWpjN/k5igSR9wZn9jnbAQyBRz:DBwMtcQKFeITp0igSOn9jXyBJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135948D21F3E0D035C85A8272BB66821D93E8BC64AD3AB18F33D43F8DDD3969165A5371
sha3_384: ff859944f2f11841587b355f5cc2a40d21fb638d449cab7c629e2433bb395bf0ca9dd9d5786010ac99f6b3f407761210
ep_bytes: 6033f20fadce0fafef35a8cb629dd1d6
timestamp: 2006-03-09 09:45:19

Version Info:

Comments: Developed by Archeng
CompanyName: Realtek Semiconductor Corp.
FileDescription: Driver Update and remove for Windows x64 or x86_32
FileVersion: 2, 6, 0, 3
InternalName: RtlUpd
LegalCopyright: Copyright (C) 2000-2005 Realtek Semiconductor Corp.
OriginalFilename: RtlUpd.EXE
ProductName: Realtek AC'97 Update and remove driver Tool
ProductVersion: 2, 6, 0, 3
Translation: 0x0409 0x04b0

Win32.Sality.OG also known as:

BkavW32.Sality.PE
LionicVirus.Win32.Sality.mA4E
Elasticmalicious (high confidence)
DrWebWin32.Sector.17
MicroWorld-eScanWin32.Sality.OG
FireEyeGeneric.mg.0b6fece0ee40dd2f
CAT-QuickHealW32.Sality.R
SkyhighBehavesLike.Win32.Infected.gh
McAfeeW32/Sality.u.gen
MalwarebytesGeneric.Malware/Suspicious
ZillyaVirus.Sality.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( f10001021 )
AlibabaVirus:Win32/Sality.4864b0f9
K7GWVirus ( f10001021 )
Cybereasonmalicious.bb38e1
BitDefenderThetaAI:FileInfector.2A9374620F
VirITWin32.Sality.BK
SymantecW32.Sality.AE
tehtrisGeneric.Malware
ESET-NOD32Win32/Sality.NAU
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Sality.sil
BitDefenderWin32.Sality.OG
NANO-AntivirusVirus.Win32.Sality.gcen
AvastWin32:Kukacka [Inf]
RisingVirus.Sality!1.A5BD (CLASSIC)
EmsisoftWin32.Sality.OG (B)
F-SecureMalware.W32/Sality.AA
BaiduWin32.Virus.Sality.e
VIPREWin32.Sality.OG
TrendMicroPE_SALITY.BU
SophosMal/Sality-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Sality.OG
JiangminWin32/HLLP.Kuku.aa
GoogleDetected
AviraW32/Sality.AA
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Sality.gen
KingsoftWin32.Sality.ab.173464
XcitiumVirus.Win32.Sality.gen@1egj5j
ArcabitWin32.Sality.OG
ViRobotWin32.Sality.Gen.A
ZoneAlarmVirus.Win32.Sality.sil
MicrosoftVirus:Win32/Sality.AM
VaristW32/Sality.AK
AhnLab-V3Win32/Kashu.B
VBA32Virus.Win32.Sality.baka
ALYacWin32.Sality.OG
Cylanceunsafe
PandaW32/Sality.AN
TrendMicro-HouseCallPE_SALITY.BU
TencentVirus.Win32.TuTu.A.200000
YandexWin32.Sality.AP.Gen
IkarusVirus.Win32.Sality
MaxSecureVirus.Sality.OG
FortinetW32/Sality.AA
AVGWin32:Kukacka [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Sality.OG?

Win32.Sality.OG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment