ComboFix, the malware removal tool, infected with Sality Virus

In a recent not-so-good development, ComboFix, the popular malware removal tool, hosted by well-known Bleeping Computers has been found to be infected with the Sality Virus and has been termed as dangerous for download.


Confirming this discovery, Lawrence Abrams says:

 “Unfortunately it has come to light that the program ComboFix had a file in it that is infected with the Sality virus. The minute we heard about this, we pulled the executable so that it is no longer available from Bleeping Computer.”

From rough information, it is known that the Sality Virus has been available in ComboFix since 2am EST on January 29th 2013 and the developer, sUBs is presently hooked on to help fix it. In the meanwhile, users are discouraged from downloading ComboFix from other mirror sites which may be hosting the program since the developers have no control on the mirror versions and there is a high probability that the infected virus sits in them.

In case you already happen to have ComboFix installed on your system, it’s highly recommended that you undertake the following steps:

  • Scan your computer with ESET’s Online Scanner.
  • Download and scan your computer with the Kaspersky Rescue Disk
  • Use SalityKiller if you are unable to use the above tools for some reason. When using this tool, you should disconnect from your network first.
  • Use AVG Sality Remover Tool. When using this tool, you should disconnect from your network first.

According to Lawrence, all of these (above) tools should be able to detect and remove Sality from your computer. Sality is also able to spread through mapped network drives and shares. If you share any folders on your network, you should perform the above steps on those computers as well.

If you visit the download page now, you will see the following message:

This download is not available at this time. We apologize for the issues and hope to have it available soon.

Users are advised to wait for developments from its developers sUBs and not download from any other mirror sites. Once a clean version of the tool is made available, you may download it from which is the official download site for Combofix.

For assistance or more details, head over to the forum post.

UPDATE: The problem has been resolved and the new version of ComboFix can be downloaded from Bleeping Computer.

ComboFix is not your regular malware scanner and should be run only under the guidance of an expert.

Posted by with Tags
Anand Khanse is the Admin of, a 10-year Microsoft MVP Awardee in Windows (2006-16) & a Windows Insider MVP. He enjoys following and reporting Microsoft news and developments in the world of Personal Computing & Social Media.

One Comment

  1. Corrine Chorney

    The problem has been resolved and a new, thoroughly tested within the
    security community, version of ComboFix has been uploaded to Bleeping
    Computer. However, the reminder continues: ComboFix should not be run unless specifically asked by a trained malware analyst. It is not an ad hoc scanner or an antivirus tool. Due to the power of this tool, it is strongly advised that you do not attempt to act upon any of the information displayed by ComboFix without supervision from someone who has been properly trained. Doing so may lead to problems with the normal functionality of your computer.It is additionally advised that ComboFix should only be downloaded from the authorized hosting location at Bleeping Computer.

Leave a Reply

Your email address will not be published. Required fields are marked *

7 + 2 =