A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #28526  by tg1489
 Wed May 18, 2016 2:56 pm
I know this is a longshot but a long time ago when virussign was completely free, I downloaded the usual 500 a day pack and found a really vicious piece of trojan/sality that I accidentally deleted. I dont remember the exact name except it was a trojan with sality. It shows up in the process list but if you try to kill it then it will give you a bsod. The original exe had a picture of the show "Arrow" on it. If anyone can help me get information on it again so I can download it I would appreciate that a lot.
 #28540  by tg1489
 Thu May 19, 2016 7:44 pm
Buster_BSA wrote:And two hard boiled eggs!
Lmao I knew it was pointless. I was just hoping somebody was collecting them throughout the months and happened to remember it. Is there a list of all the sality variants I can find?
 #28545  by EP_X0FF
 Fri May 20, 2016 4:45 pm
Your description is too generic. From It - malware process set as system "Critical" (RtlSetProcessIsCritical), popular "feature" of noob malware and it in wide variety of cheap malware obfuscators.