Combofix has been infected with Sality! Do Not use!


Recommended Posts

Combofix has been infected with Sality! Do Not use!!!!

Unfortunately it has come to light that the program ComboFix had a file in it that is infected with the Sality virus. The minute we heard about this, we pulled the executable so that it is no longer available from BleepingComputer.com. Unfortunately we have no control over other sites that may have mirrored ComboFix without permission, so please do not attempt to download it elsewhere.

The developer, sUBs, is currently looking into what happened and when I have a full update, I will be sure to let you know. From the limited information that I have, it appears that the affected version has been available since approximately 2am EST on January 29th, but it may have been earlier. If this timeframe changes, I will update this topic to let you know. If you have used a new copy of ComboFix in the last day or so, then you should examine your system for possible infection. If you have used a copy of ComboFix prior to this version, then you should be ok.

SHA256 Hashes of known affected versions are:

4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333

e5341c3c32a9726a2d3dd1ac0b90f13d896581ab8707dd0a17431df061a2a71d

4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333

e95f77fd437b16312fbd66a02fed8b179968a7615c1bd3cd3b2fd86879b4bbc8

In the meantime, it is important for those who may have used ComboFix recently and are concerned they are infected to get the help they need. As the Sality infection has been around for a while, almost all antivirus vendors will have detected it and blocked it when you ran ComboFix. Unfortunately, not everyone has up-to-date virus definitions or uses an AV program, so it is important to examine your system if you have downloaded a new copy and used it since 2am EST.

The steps we suggest you take to make sure your computer is not infected are:<p>

http://www.bleepingcomputer.com/forums/topic483431.html

Just downloaded and used combo fix yesterday. Also scanned with MSE, Malwarebytes, and Spybot afterwards. None of the scans picked up anything but i'm scanning with ESET's Online Scanner now just in case.

Thanks for the heads up warwagon.

Luckily, you got it before the infection if you downloaded yesterday.

Yeah but it seems I'm infected anyhow.

Yr2GFFj.png

How all these scanners I've used and they all missed all at...smh I guess its been a few years since I formatted anyway.

Those might not be infections per say, just the exploit files left over in your java cache folder. What are the locations of those files?

Those might not be infections per say, just the exploit files left over in your java cache folder. What are the locations of those files?

He should turn off java's temp file option. I used to see those exploit names on users pc's, but since i turn off the temp file option, i haven't seen those appear.

Unfortunately it has come to light that the program ComboFix had a file in it that is infected with the Sality virus. The minute we heard about this, we pulled the executable so that it is no longer available from BleepingComputer.com. Unfortunately we have no control over other sites that may have mirrored ComboFix without permission, so please do not attempt to download it elsewhere.

The developer, sUBs, is currently looking into what happened and when I have a full update, I will be sure to let you know. From the limited information that I have, it appears that the affected version has been available since approximately 2am EST on January 29th, but it may have been earlier. If this timeframe changes, I will update this topic to let you know. If you have used ComboFix in the last day or so, then you should examine your system for possible infection. If you have used a copy of ComboFix prior to this version, then you should be ok.

Quote from BleepingComputer Admin:

ComboFix is now live, clean, and available to download from its normal links.

They have it sorted apparently, the executable is now live again at BleepingComputer.

Read More Here

Hello,

I am unsure of how that might have helped in this particular situation. From what I understand of the issue, it was the build machine that was infected.

Regards,

Aryeh Goretsky

Yeah but it seems I'm infected anyhow.

Yr2GFFj.png

How all these scanners I've used and they all missed all at...smh I guess its been a few years since I formatted anyway.

That's not sality, trust me :)I cleaned a few computers from it, and it's specifically say w32 something sality. it'll also start writing stuff to any USB stick you put in it.

The only tool that managed to get rid of it was the Kaspersky sality killer, followed by the Sality remover which I believe is form AVG based on the logo.

I'm guessing this was an unsigned executable? Time to get a code signing certificate.

Thing is, if you had an infected combofix, it didn't actually run, it'd just give an error that it was invalid, but sality would still infect since it had taken over the exe, but combofix itself wouldn't run with the infected file.

Good thing they got it fixed anyway, since it's the absolute best tool to clean computers.

the computer I cleaned g in with sality got it from somewhere else though, since that person wouldn't know a virus cleaner if it slapped her in the face. over 600 infected files, a lot of them sality, but also a whole bunch of other stuff.

be warned that sality does appear to somehow get through even with autplay off. if you're cleaning. Her computer will need a full recovery though, hopefully it doesn't infect the recovery partition.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Samsung introduces new AI classroom tools and interactive displays at ISTELive 2026 by Fiza Ali Samsung has announced several new education-focused software features and interactive displays for schools during ISTELive 2026, taking place in Orlando, Florida, from 28 June to 1 July. The focus of these updates is on making shared classroom displays easier to use for teachers while giving IT administrators more control over managing devices. One of the key additions is the Samsung Account Management Solution (AMS). In many schools, multiple teachers share the same interactive display throughout the day, which means signing in and setting everything up can become repetitive. With AMS, teachers can log in by scanning a QR code or tapping an NFC-enabled ID card. Once signed in, their personalised workspace, including wallpapers, bookmarks, app shortcuts, and files, can be instantly accessed through Home Personalisation. Samsung has also included a screen lock feature, allowing teachers to lock the display if they need to step away briefly. Furthermore, the company is also updating its Education Portal with new tools designed for school IT administrators. The portal will allow IT administrators to register teachers, enrol devices, and manage user access from a central dashboard. Administrators can also link NFC cards to teacher accounts, making sign-ins quicker across shared displays. Another addition is a Tags feature that lets schools organise displays by building or classroom. Those tags can also be used to send emergency notifications to selected Samsung Interactive Displays through compatible platforms such as InformaCast and Raptor. Moreover, the tech giant's AI Assistant is gaining several new features aimed at supporting everyday classroom tasks such as lesson planning and classroom engagement. One of the features is Circle to Search, which lets teachers circle text or images on the display to quickly find related information, videos, or web results without interrupting the lesson. The content can then be brought into Samsung Whiteboard. Another feature, Live Transcript, converts spoken lessons into real-time captions, which could be useful for students with hearing impairments or those in multilingual classrooms. The AI Assistant also introduces AI Summary and AI Quiz. The summary tool creates summaries of recorded lessons, while AI Quiz generates questions based on lesson content so teachers can quickly check how well students are following along. Teachers signed in through Samsung AMS can also return to their previous AI-generated lesson materials without logging in again. Alongside the software updates, Samsung has expanded its Android-based Interactive Display range with three new models: the WAF-S, WAFX-PS, and WAHX-M. The WAF-S and WAFX-PS ship with Android 16, bringing updates to security, accessibility, and overall usability while maintaining compatibility with Google's education services including Google Classroom and Google Drive through EDLA certification. Meanwhile, the new WAHX-M is the biggest addition to the lineup, introducing a 98-inch display for larger spaces such as lecture halls and conference rooms. It will also be available in 65-inch, 75-inch and 86-inch sizes. Samsung says the WAHX-M further includes on-device AI features such as voice commands, text-to-speech, and an AI calculator, alongside support for Samsung AMS and AI Assistant. Samsung AI Assistant has been available since April, while Samsung AMS and the updated Education Portal will begin rolling out in July.
    • It's been $24 (single) or $89 (4-pack) for many days on both Amazon and Walmart as far as I know. That isn't a big discount. If these end up like the 1st gen, the 4-pack will routinely get down around $80, give or take a dollar. I think they have even hit $69 at times.
    • Microsoft brings Claude to its own Azure infrastructure, powered by Nvidia GB300 Blackwell by Karthik Mudaliar Anthropic's Claude models are now generally available in Microsoft Foundry on Azure and are running on Nvidia's GB300 Blackwell Ultra systems. Nvidia wrote in its announcement that the models are hosted on Microsoft Azure and accelerated by GB300 Blackwell Ultra GPUs, with Quantum-X800 InfiniBand networking used to support larger agentic systems and specialized sub-agents that can operate across business domains. This is great for customers and enterprises that want to build autonomous and domain-specific AI agents using Claude without moving outside Microsoft’s cloud platform. Microsoft currently offers Claude models in Foundry in two forms: “Hosted on Azure,” which runs end-to-end on Azure infrastructure and is generally available, and “Hosted on Anthropic infrastructure,” which remains in preview. This separation is quite important for organizations that have procurement, compliance, data processing, or internal governance requirements tied to Azure. Anthropic currently has 11 Claude models listed in Microsoft Foundry, including Opus 4.8, Sonnet 4.6, and even the unavailable Mythos and Fable models. Billing is handled through Claude Consumption Units (CCUs). Microsoft says CCU is an invoicing unit for Claude models in Foundry, with token usage converted using Anthropic’s published per-model token rates. The usage is billed through Azure Marketplace just like models from other distributors and appears on the customer's Azure invoice, while eligible spend can count against a Microsoft Azure Consumption Commitment. For starters, GB300 NVL72 is a rack-scale, fully liquid-cooled system that combines 72 Blackwell Ultra GPUs and 36 Grace CPUs. Nvidia has listed 37TB of fast memory, 130TB/s of NVLink bandwidth, and FP4 Tensor Core performance of up to 1,440 petaflops with sparsity. The deal is also part of a three-way partnership between Microsoft, Nvidia, and Anthropic. Under the deal, Anthropic has committed to buying $30 billion in Azure compute capacity and contracting additional capacity up to one gigawatt. Nvidia and Microsoft also said they would invest up to $10 billion and $5 billion in Anthropic, respectively.
    • WhatsApp is getting usernames, and you can reserve your preferred one now by Fiza Ali Sharing your phone number isn't always something you want to do, especially with people you've just met. Whether it's someone from a class, a local community group, or a sports team chat, handing over your number can feel like giving away more personal information than necessary. That's exactly the problem WhatsApp is trying to solve with its upcoming usernames feature. The company has announced that users can now reserve a unique WhatsApp username ahead of the feature's wider rollout later this year. Once usernames become available, they'll let people connect without revealing their phone numbers. It's a change that makes a lot of sense for group chats. Right now, everyone in the group can see your phone number. With usernames enabled, that won't necessarily be the case when someone contacts you for the first time. WhatsApp says it's opening username reservations early because more than three billion people use the app, meaning plenty of people are likely to want the same usernames. Reserving one now gives users a better chance of securing the name they actually want before the feature launches more broadly. If your preferred username is already taken, WhatsApp will also offer a built-in username generator to suggest available alternatives. The feature isn't only aimed at individual users. Creators, businesses, and organisations will be able to claim the same username they already use on Instagram or Facebook, making it easier to keep a consistent identity across Meta's apps. Furthermore, privacy is a big part of how WhatsApp is introducing usernames. There won't be a public directory where people can browse or search for usernames. Instead, people will need to know your exact username before they can start a conversation with you. Additionally, users can also choose to enable a username key, which adds another layer of control by requiring people to enter that key before sending a message. Once the feature rolls out, people who choose to use a username will no longer have their phone number shown when messaging a person or business for the first time. If you want to reserve a username, make sure you're running the latest version of WhatsApp, then head to Settings > Account > Username. The tech giant says usernames will roll out gradually over the coming months, and users will receive an in-app notification when the feature becomes available in their country.
    • When I think about a network, there are really two aspects, the hardware and the wiring. So here is what I would do for both. Wiring: Use Cat6A for the patch panel, outlets, and all structured cables (cables installed in walls). Run plenty of Wireless Access Point (WAP) cables, as a general rule, assume a signal can only pass through 2-3 walls and can't pass through a floor (that is conservative, but trust me on this if you want strong WiFi)  Cat6 patch cables are fine for now if you don't plan to run 10gig, those are easy to replace later if needed. Run OS2 single-mode fiber to anywhere you think you may have a server or sub-switch. (yes, single-mode for everything on a small network, don't mess with multimode unless you are at a scale where that minor cost and power savings will matter). If you really want to future proof, also run fiber to any high density WAP locations, it is likely that WiFi 8 and beyond WAPs will push the limits of 10g. Run 6-12 pairs of single-mode fiber between your MDF and the building's MDF, even if you only need 1 or 2 pairs now, those extra pairs will pay off down the road. Hardware: (its easy to say "get all the features incase you need them", so instead of futureproofing, I am going to take approach of suggesting areas worth investing in, and areas you can save money). Don't overspend thinking you need every feature on every port. You don't need 10g on every port, you don't need PoE on every port. Don't overspend on redundancy either, unless you are ready to buy two of everything, don't waste money buying two of some things and not others. Dual power supplies are worthwhile, but probably not HA or multi-path redundancy.  Get 1 "distribution layer" switch that your router/firewall will connect to as well as all your access layer switches below. This should be a fully managed 10g+ switch with a combination of copper and SPF ports, a few 25g uplink ports are nice for this switch. Given that you said it is a small network, I suggest also using that distribution layer switch for servers and WAPs, meaning it will need PoE. Speaking of wireless, get good professional tri-band WAPs, and either turn on the band stirring options, or limit 2.4 to an IoT only SSID. This will provide a solid WiFi capable nearly everything but the highest of bandwidth clients...you could even consider skipping wiring workstations depending on usage. Access layer switch for workstations and printers can be cheaper switches, 2.5g is a good sweet spot between price and future proofing, but even 1g is fine for most individual clients (the kind that could probably be fine on WiFi). You can consider saving a little on access layer switches by only getting 1 PoE switch for whatever needs it (remember your WAPs are connecting to the distribution switch, not here), and non-PoE for your workstations, because desk phones are falling out of favor. You can also save money here by not buying managed switches if you don't need them--but really do some soul searching there, if you go this route, then anything that isn't on your workstation VLAN would either need to be connected to the distribution switch, or its own access layer switch. Also, don't feel like you need a fancy fabric stacking switches for your access layer, that is the point of the higher-end distribution layer, to remove the need for things like that at this level. Home Hardware: I'm realizing the above assumed an office setting, if this if for your house and home lab then the above still applies, but you'll probably want everything managed and PoE, just because, but you probably also don't need multiple access layer switches. If your total port count is below 24, just skip separating distribution layer and access layer and just get one nice switch with the features you want. If you are at the point of considering a 48-port switch, I would instead get a nice high-end distribution switch for things that need it, and cheaper access layer switches with specs based on the needs of connected devices. For home use, don't worry about home running every device to the main switch, there is nothing wrong with running sub-switches for your media areas and office, those essentially become your access layer, just look for sub-switches with a 10g uplink so sharing bandwidth isn't an issue. Just make sure you always connect them to your distribution/main switch, don't daisy chain, the path should never have more steps than Client>Access>Distribution>Firewall>Internet or Client>Access>Distribution>Server if it is local.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      536
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!