In order to disinfect a computer from Virus.Win32.Sality, do the following:
If infected computers are in the local network under domain control:
Step 1. Preparation to disinfection:
- Download the file SalityKiller.zip
- Unpack the file SalityKiller.zip
- Run the file SalityKiller.exe on each computer in turn
- Run the utility SalityKiller.exe on the infected computers once again (no additional commands to run the utility are needed).
- A reboot might require after disinfection.
- Make sure that the anti-virus icon in system tray has turned red thus indicating the anti-virus software is fully functional. If otherwise, reinstall the anti-virus
- Update the anti-virus databases (signature threats)
- set the full scan options to their maximum scan level
- run full computer scan
- Anti-Virus is running and works in normal mode
- full computer scan does not detect infected objects on the computer
- download the file Sality_RegKeys.zip
- unpack the file Sality_RegKeys.zip
- run the file Disable_autorun.reg from the archive Sality_RegKeys.zip
You can also disable autorun from all devices by running the SalityKiller utility with parameter -a. - Click Yes to confirm adding the information to the registry
- once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
- under Windows 2000 run the registry file SafeBootWin200.reg
- under Windows XP run the registry file SafeBootWinXP.reg
- under Windows 2003 run the registry file SafeBootWinServer2003.reg
- under Windows Vista / 2008 run the registry file SafebootVista.reg
- under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg
If infected computer are not in the network
- Download and unpack the file SalityKiller.zip
- Run the file SalityKiller.exe
- A reboot might require after disinfection.
- Go to Start > All programs > right-click Startup > select Open
- Right-click any place in the Startup folder
- In the menu select New > Shortcut
- In the Create Shortcut window click Browse
- Browse the folder into which the file SalityKiller.exe was unpacked
- Highlight the file SalityKiller.exe
- Click the OK button
- Click Next
- Click OK
- Download the file Sality_RegKeys.zip
- Unpack the file Sality_RegKeys.zip
- Run the file Disable_autorun.reg from the archive Sality_RegKeys.zip
You can also disable autorun from all devices by running the SalityKiller utility with parameter -a. - Click Yes to confirm adding the information to the registry
- Update the anti-virus databases (threat signatures). If you cannot download the necessary databases (threat signatures) form the Internet, update the databases from the zip archives:
- set the full scan options to their maximum scan level
- run full computer scan
- once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
- under Windows 2000 run the registry file SafeBootWin200.reg
- under Windows XP run the registry file SafeBootWinXP.reg
- under Windows 2003 run the registry file SafeBootWinServer2003.reg
- under Windows Vista / 2008 run the registry file SafebootVista.reg
- under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg
You can restore the registry branch SafeBoot which is needed for a PC to be able to boot in safe mode, by running SalityKiller.exe with parameter -j.Additional parameters to run SalityKiller.exe from command line:
-p <path> - scan a specific folder;
-n - scan network disks;
-r - scan flash drives, scan removable hard disks connected via USB and Fire Wire;
-y - close the window when the utility finishes;
-s - scan in "silent" mode (without opening console box);
-l <file_name> - write log to the file;
-v - detailed logging (must be used in combination with -l);
-x - restore possibility to view hidden and system files;
-a - disable autorun from any devices;
-j - restore the registry branch SafeBoot (if it is deleted, the PC will not be able to start up in Safe mode);
-m - monitoring mode to protect the system from getting infected;
-q - scan the system and then go to monitoring mode;
-k – the utility will scan all disks, detect files autorun.inf created by the virus Virus.Win32.Sality and eliminate them. It will also delete the executable file linked by autorun.inf, even if such file has been already disinfected.
Taken from this
No comments:
Post a Comment