Sunday, March 24, 2013

Solution by Kaspersky : How to disinfect my computer from Virus.Win32.Sality

Courtesy and Credit of this post Goes to : http://support.kaspersky.com
The recommendations given concerning disinfection of a computer from Virus.Win32.Sality should be applied only if NO Kaspersky Lab product is installed on an infected computer, and/ or if the computer is already infected and a Kaspersky Lab product cannot be installed by regular means. Kaspersky Lab experts also recommend using Rescue Disk to disinfect an infected computer.

In order to disinfect a computer from Virus.Win32.Sality.aa, Virus.Win32.Sality.ae, Virus.Win32.Sality.ag, Virus.Win32.Sality.bh, use the utility SalityKiller.


1. How to disinfect hosts included in the local network under domain control

Step 1. Preparation to disinfection.
  1. Download the file SalityKiller.exe. You can find the info how to download a file on the following pages:
  2. Run the file SalityKiller.exe on each computer in turn (for example, using the server group policy in Kaspersky Administration Kit or Kaspersky Security Center).
    • On all computers on which the domain administrator can register and work.

    • While disinfecting this group of the computers do not log on under domain administrator on any other computers to prevent further spread of the infection in the network.
    • On all other computers.
    Do not stop or terminate work of the utility until all computers in the network have been disinfected!
Step 2. Algorithm of computer disinfection. Computers on which you log on under a domain administrator rights should be disinfected first. Once these computers are disinfected, start disinfecting other computers in the network.
  1. Run the utility SalityKiller.exe on the infected computers once again. A reboot might be required after disinfection.
  2. Make sure that the anti-virus icon in system tray has turned red thus indicating the anti-virus software is fully functional. If otherwise, reinstall the anti-virus using Administration Kit or Kaspersky Security Center.
  3. Update the anti-virus databases (signature threats) for the Kaspersky Lab product installed on your PC. If you cannot download the updates from the Internet, use the update utility Kaspersky Updater Utility 2.0.
  4. Set the full scan options to their maximum scan level.
  5. Run full computer scan.
Step 3. Signs of a disinfected/ clean computer.
  • Kaspersky Lab product is running and works in normal mode.
  • Full computer scan does not detect infected objects on the computer.
Step 4. Cleaning the registry of infected computers in the domain network.
  1. Download the file Sality_RegKeys.zip. You can find the info how to download a file on the following pages:
  2. Unpack the file Sality_RegKeys.zip (using WinZip).
  3. Run the file Disable_autorun.reg from the archive Sality_RegKeys.zip.


    You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.
  4. Click Yes to confirm adding the information to the registry.

  1. Once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
    • under Windows XP run the registry file SafeBootWinXP.reg.
    • under Windows 2003 run the registry file SafeBootWinServer2003.reg.
    • under Windows Vista / 2008 run the registry file SafebootVista.reg.
    • under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg .
    • under Windows 8 run the registry file SafeBootWin8.reg.

2. How to disinfect hosts that are not in the network

To disinfect computers that are not in the network, do the following:
  1. Disable the technologies iSwift and iChecker, if one of the following products is installed and running on your PC:
    • Kaspersky Anti-Virus 6.0/7.0/2009/2010/2011/2012/2013
    • Kaspersky Internet Security 6.0/7.0/2009/2010/2011/2012/2013
    • Kaspersky PURE;
    • Kaspersky Anti-Virus 6.0 for Windows Workstations
    • Kaspersky Anti-Virus 6.0 SOS
    • Kaspersky Anti-Virus 6.0 for Windows Servers
  2. Download and unpack the file SalityKiller.exe. You can find the info how to download a file on the following pages:
  3. Run the file SalityKiller.exe
  4. A reboot might be required after disinfection.
  5. With an installed Kaspersky Lab product you might be prompted to allow any activity to the process Sality_killer.exe
    • Go to Start > All programs > Startup.
    • Right-click Startup > select Open.

    • Right-click any place in the Startup folder. In the menu select New > Shortcut.

    • In the Create Shortcut window click Browse.
    • Browse the folder into which the file SalityKiller.exe was unpacked.
    • Select the file SalityKiller.exe.
    • Click the OK button.
    • Click Next.
    • Click OK.
  1. Download the file Sality_RegKeys.zip. You can find the info how to download a file on the following pages:
  2. Unpack the file Sality_RegKeys.zip (using WinZip).
  3. Run the file Disable_autorun.reg from the archive Sality_RegKeys.zip. You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.
  4. Click Yes to confirm adding the information to the registry.

  1. Update the anti-virus databases (threat signatures) for the installed Kaspersky Lab product. If you cannot download the necessary databases (threat signatures) form the Internet, then use the update utility Kaspersky Update Utility 2.0.
  2. Set the full scan options to their maximum scan level.
  3. Run full computer scan.
  4. Once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
    • under Windows XP run the registry file SafeBootWinXP.reg;
    • under Windows 2003 run the registry file SafeBootWinServer2003.reg;
    • under Windows Vista / 2008 run the registry file SafebootVista.reg;
    • under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg;
    • under Windows 8 run the registry file SafebootWin8.reg.
You can restore the registry branch SafeBoot which is needed for a PC to be able to boot in the safe mode, by running SalityKiller.exe with parameter -j.

3. Additional switches to run SalityKiller.exe from command line

-p <path> - scan a specific folder;
-n - scan network disks;
-r - scan flash drives, scan removable hard disks connected via USB and Fire Wire;
-y - close the window when the utility finishes;
-s - scan in "silent" mode (without opening console box);
-l <file_name> - write log to the file;
-v - detailed logging (must be used in combination with -l);
-x - restore possibility to view hidden and system files;
-a - disable autorun from any devices;
-j - restore the registry branch SafeBoot (if it is deleted, the PC will not be able to start up in Safe mode);
-m - monitoring mode to protect the system from getting infected;
-q - scan the system and then go to monitoring mode;
-k – the utility will scan all disks, detect files autorun.inf created by the virus Virus.Win32.Sality and eliminate them. It will also delete the executable file linked by autorun.inf, even if such file has been already disinfected.

Courtesy : http://support.kaspersky.com/1874?vs=s88446#s88446