How to remove latest win32.sality and Trojan viruses

By avrajan82 ·
I have faced the problem in my company that sality virus regenerating inside after detecting and cleaning. Currently we are using Symantec Endpoint Protection. But the virus spreading over the network and immediately disables the Symantec Antivirus and also I have tried to clean using lots of tools like rmsality, sality killer, combofix, dr.web, rescue disc, even many antivirus like Kaspersky, McAfee, Symantec, AVG, etc. nothing can detect this main virus, its detect something but regenerating itself. Kindly give me a solution. Thank you for your extreme help.

This conversation is currently closed to new comments.

Thread display: Collapse - | Expand +

All Answers

Collapse -

Well, it is going to be extreme, certainly.

by seanferd In reply to How to remove latest win3 ...

What you will have to do is remove each node from the network, clean it, leave it disconnected until all other nodes have been cleaned.

I told you it would be extreme. But this is the only way to even begin to address the problem.

What really should be done, in addition to the above, is to back up data, wipe each hard drive with something like DBAN, then re-image or re-install the OS and applications.

You can try Symantec's method:
But it is still critical that no machine be reattached to the network until every other machine has been cleaned.

No user should be running an Administrator account during normal use. This just makes infections like this worse.

Other information:
You may also search the other names given to this malware.

Related Discussions

Related Forums