How to remove Win32/Sality.NAR virus ?

Discussion in 'NOD32 version 2 Forum' started by dsi-ap, Aug 14, 2008.

Thread Status:
Not open for further replies.
  1. dsi-ap

    dsi-ap Registered Member

    Joined:
    Jul 4, 2005
    Posts:
    118
    Location:
    UK
    Had a few machines now infected with this virus Win32/Sality.NAR and on the machines running v2.70 of NOD we find not is disabled completely by the virus.

    The virus is able by the looks of it close running applications/exe's and infected them.

    Only when updating to ESET NOD32 Antivirus Business Edition (32-bit) 3.0.669 did the antivirus start working and detecting all the Sality.nar viruses, but the system is overwhelmed and only soultuion is to completely format systems affected by this virus.

    Is there a guide somewhere how to cleanse/wipe out this virus without a trace and not have to rebuild entire systems.

    Thanks

    Note: The virus also disable the taskmanager & restore points no longer show or available in XP/Vista.
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    The cleaning depends on whether the system files are infected or not (I assume they are). In such case, the best would be to slave the disk, boot from a clean one and run a scan of the infected disk. If cleaning is not possible, send about 10 infected files in a password protected archive to samples[at]eset.com with a link to this thread and we'll see if it's technically possible to clean them.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.