Malware

About “Win32:Sality-KYG” infection

Malware Removal

The Win32:Sality-KYG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Sality-KYG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Win32:Sality-KYG?


File Info:

name: F50D01F32A48696BA47E.mlw
path: /opt/CAPEv2/storage/binaries/6815a2e7c9667e6044ae1d2f8919a8d39bb2813b5d5a105da823e019df361b18
crc32: D9553D61
md5: f50d01f32a48696ba47e8185aaff3c15
sha1: 6ecbb7f5955b6783bf9ccfd4091ad2d87ccd81ad
sha256: 6815a2e7c9667e6044ae1d2f8919a8d39bb2813b5d5a105da823e019df361b18
sha512: ac2c9355dc6e3bf019b7a90d92e617cf51bd657fd761262de0d7649c78a7bf4c66f9e1a7001c9942e7003249350da3b2298a26e69931bee1617e2ec33c5319e1
ssdeep: 768:cdl4bWZtBTSD9mx0CjIGhY4VVN2b1LllfRddcQVEWeSgPl53XXT+AeZO:cdWoq9Cr0GhXKdTdTiWeDPv3XAZO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E93A53FBF864066E548563026F6C7E61ABB581B5B2B100BE704F7552DE7E240C2CEA7
sha3_384: 6bd41b576996b0439bd17d31c5f24933b28b3e1c09456dbcf31f48e355cb5a05dc16875e16656362dfc90ab22a9c18a3
ep_bytes: 68bc124000e8eeffffff000000000000
timestamp: 2012-10-08 17:42:11

Version Info:

Translation: 0x0409 0x04b0
ProductName: lapithae
FileVersion: 0.40
ProductVersion: 0.40
InternalName: Confed
OriginalFilename: Confed.exe

Win32:Sality-KYG also known as:

BkavW32.AIDetectMalware
AVGWin32:Sality-KYG
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.2430
FireEyeGeneric.mg.f50d01f32a48696b
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.nm
ALYacGen:Variant.Symmi.2430
MalwarebytesPronny.Worm.Spreader.DDS
VIPREGen:Variant.Symmi.2430
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.fm0@am6iPili
VirITWorm.Win32.VB.KK
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.FR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1717
KasperskyWorm.Win32.Vobfus.wdd
BitDefenderGen:Variant.Symmi.2430
NANO-AntivirusTrojan.Win32.Vobfus.cmxpyc
AvastWin32:Sality-KYG
TencentMalware.Win32.Gencirc.10b1515d
EmsisoftGen:Variant.Symmi.2430 (B)
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.27439
TrendMicroWORM_VOBFUS.SMQ5
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
VaristW32/VB.HE.gen!Eldorado
AviraTR/Downloader.Gen8
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.Pronny.EB@4qtzpj
ArcabitTrojan.Symmi.D97E
ZoneAlarmWorm.Win32.Vobfus.wdd
GDataGen:Variant.Symmi.2430
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R39146
McAfeeGenDownloader.rv
TACHYONWorm/W32.Vobfus.94208
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMQ5
RisingWorm.Vobfus!8.10E (TFE:3:L0fVyQLT3SL)
YandexTrojan.GenAsa!HzAOoEFks5w
IkarusWorm.Win32.VBNA
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.1211a966

How to remove Win32:Sality-KYG?

Win32:Sality-KYG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment