Advice Request Kaspersky suddenly detected setup files of legit software

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

Dhruv2193

Level 10
Thread author
Verified
Well-known
Nov 7, 2016
468
In the laptop of one of my family members, kaspersky was installed and today it suddenly started detecting setups of legit programs like kerish doctor, idm, gom player as win.32.sality.gen. It disinfected them but it did not detect them for a week.
Update- Kaspersky was right in detecting the files as they were infected.
 

Attachments

  • Capture.PNG
    Capture.PNG
    57.2 KB · Views: 551
Last edited:
L

Local Host

Could be legit,

Virus:Win32/Sality.gen!Q is a generic detection for a virus that spreads by infecting Windows executable files and by copying itself to removable and remote drives. It also terminates various security products, prevents certain Windows utilities from executing and attempts to download additional files from a predefined remote Web server.
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
In the laptop of one of my family members, kaspersky was installed and today it suddenly started detecting setups of legit programs like kerish doctor, idm, gom player as win.32.sality.gen. It disinfected them but it did not detect them for 1 week. Your thoughts?

I think you should check/scan yout PC with some 3rd party app (like. HitmanPro, Norton Power Eraser, Emsisoft Emergancy Kit...)
 

Dhruv2193

Level 10
Thread author
Verified
Well-known
Nov 7, 2016
468
Will do the same and reply about the result.

I scanned with malwarebytes it did not find any threat but zemana did - the same malware. Maybe a malware really infected the setup. I also got a reply from kaspersky that it was not a false detection.
 
Last edited by a moderator:

CoherentCrayon

Level 4
Verified
Jun 23, 2017
183
I scanned with malwarebytes it did not find any threat but zemana did - the same malware. Maybe a malware really infected the setup. I also got a reply from kaspersky that it was not a false detection.
I would have scanned with HitmanPro also to make sure you have no virus on your computer (it seems like you have a virus which infects your files?). Also you need to enable rootkit scanning in the Malwarebytes options for it to scan for rootkits.

/steel9
 

RoboMan

Level 35
Verified
Top Poster
Content Creator
Well-known
Jun 24, 2016
2,400
On the CCleaner infection hype, some antivirus detected the installer as malware right before the news about it went viral. What i mean, is: if it happened to CCleaner there's no reason why more people couldn't go in attacking this kind of companies. It's most likely to be malware that infected those files, but it's a possibility those servers were compromised. Just an opinion.
 

Transhumana

Level 6
Verified
Well-known
Jul 6, 2017
271
If malware infected files, would it change it's hash? If so, you could compare the hash of the legit setup file and the infected one on the computer. If it's different then malware might have infected the file after it was downloaded. If it's the same, could it be that it was already infected when it was downloaded from the server?
I'm not sure if it makes sense, and if it doesn't please correct me.
 
L

Local Host

If malware infected files, would it change it's hash? If so, you could compare the hash of the legit setup file and the infected one on the computer. If it's different then malware might have infected the file after it was downloaded. If it's the same, could it be that it was already infected when it was downloaded from the server?
I'm not sure if it makes sense, and if it doesn't please correct me.
It was detected days after it was downloaded according to OP, so it's safe to say the file was infected after and didn't come from the server infected. Not to mention Win32/Sality.gen is a known variant, so it would be detected the moment he tried to download the files.
 

brambedkar59

Level 29
Verified
Top Poster
Well-known
Apr 16, 2017
1,875
In the laptop of one of my family members, kaspersky was installed and today it suddenly started detecting setups of legit programs like kerish doctor, idm, gom player as win.32.sality.gen. It disinfected them but it did not detect them for a week.
Update- Kaspersky was right in detecting the files as they were infected.
Did you inserted any USB drive in that device at that time? It's a pretty nasty infection. Even if Kaspersky has removed the malware, I would suggest you to open a thread in malware removal too, just to be sure
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top