How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/ with Kaspersky Tools

April 20, 2010 by  
Filed under Removal Tips,Tools and Videos

Views 15,523 views  
FaceBook Logo FB Comments
Comments 7 Comments

The recommendations given concerning disinfection of a computer from Virus.Win32.Sality should be applied only if NO Kaspersky Lab product is installed on an infected computer, and/ or if the computer is already infected and a Kaspersky Lab product cannot be installed by regular means. Kaspersky Lab experts also recommend using Rescue Disk to disinfect an infected computer.


The SalityKiller.exe utility given in this article allows detecting and disinfecting only the following Sality modification Virus.Win32.Sality.aa,


In order to disinfect a computer from Virus.Win32.Sality.aa, do the following:


If infected computers are in the local network under domain control:

Step 1. Preparation to disinfection:

  • Download the file
  • Unpack the file
  • Run the file SalityKiller.exe on each computer in turn (for example, through Kaspersky Administration Kit, or the server group policy).
    • on all computers on which the domain administrator can register and work

While disinfecting this group of the computers do not log on under domain administrator on any other computers to prevent further spread of the infection in the network.

    • on all other computers

Do not stop or terminate work of the utility until all computers in the network have been disinfected.


Step 2. Algorithm of computer disinfection.

Computers on which you log on under a domain administrator rights should be disinfected first. Once these computers are disinfected, start disinfecting other computers in the network.

Step 3. Signs of a disinfected/ clean computer

  • Kaspersky Anti-Virus is running and works in normal mode
  • full computer scan does not detect infected objects on the computer

Step 4. Cleaning the registry of infected computers in the domain network:

  • download the file
  • unpack the file
  • run the file Disable_autorun.reg from the archive

    You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.

  • Click Yes to confirm adding the information to the registry

  • once the scan is over, from the archive run the file of the registry key: 
    • under Windows 2000 run the registry file SafeBootWin200.reg
    • under Windows XP run the registry file SafeBootWinXP.reg
    • under Windows 2003 run the registry file SafeBootWinServer2003.reg
    • under Windows Vista run the registry file SafebootVista.reg


If infected computer are not in the network

  • Disable the technologies iSwift and iChecker, if one of the following products is installed and running on your PC:
    • Kaspersky Anti-Virus 7.0
    • Kaspersky Internet Security 7.0
    • Kaspersky Anti-Virus 6.0
    • Kaspersky Internet Security 6.0
    • Kaspersky Anti-Virus  2009;
    • Kaspersky Internet Security 2009;
    • Kaspersky Anti-Virus  2010;
    • Kaspersky Internet Security 2010;
    • Kaspersky Anti-Virus 6.0 for Windows Workstations
    • Kaspersky Anti-Virus 6.0 SOS
    • Kaspersky Anti-Virus 6.0 for Windows Servers
  • Download and unpack the file
  • Run the file SalityKiller.exe

With an installed Kaspersky Lab product you might be prompted to allow any activity to the process Sality_killer.exe

    • Go to Start > All programs > right-click Startup > select Open


    • Right-click any place in the Startup folder
    • In the menu select New > Shortcut
    • In the Create Shortcut window click Browse
    • Browse the folder into which the file SalityKiller.exe was unpacked
    • Highlight the file SalityKiller.exe
    • Click the OK button
    • Click Next
    • Click OK


  • Download the file
  • Unpack the file
  • Run the file Disable_autorun.reg from the archive


    You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.

  • Click Yes to confirm adding the information to the registry


You can restore the registry branch SafeBoot which is needed for a PC to be able to boot in safe mode, by running SalityKiller.exe with parameter -j.

Additional parameters to run SalityKiller.exe from command line:

p <path> – scan a specific folder;
-n – scan network disks;
-r – scan flash drives, scan removable hard disks connected via USB and Fire Wire;
-y – close the window when the utility finishes;
-s – scan in “silent” mode (without opening console box);
-l <file_name> – write log to the file;
-v – detailed logging (must be used in combination with -l);
-x – restore possibility to view hidden and system files;
-a – disable autorun from any devices;
-j – restore the registry branch SafeBoot (if it is deleted, the PC will not be able to start up in Safe mode);
-m – monitoring mode to protect the system from getting infected;
-q – scan the system and then go to monitoring mode;
-k – the utility will scan all disks, detect files autorun.inf created by the virus Virus.Win32.Sality and eliminate them. It will also delete the executable file linked by autorun.inf, even if such file has been already disinfected.



FaceBook Comments


7 Responses to “How To Remove and fix Virus.Win32.Sality Win32/Sality.ah Win32/ with Kaspersky Tools”
  1. Virus Removal Tool says:

    I was just writing a post on my blog about removing this virus, and was wondering if removing it manually will really help and moreover work without any “side effects”? I mean was this technique you posted tested or by now maybe the definition file of all teh major AV’s can do the job?


  2. admin says:

    Thanks for your comment.

  3. anvilonthebutt says:

    how does sality killer works?? does it delete any .exe that is infected by the virus or it “REPAIRS” the infected file??

  4. Rahulmg says:

    It Will Repair/Cure the Sality infected Files, if it is Possible to repair. Kaspersky Salitykiller Tool Repairs Sality.aa, and other Sality variations.

  5. Thomas says:

    I did the same thing but using Avira as antivirus. It did the same good job as Kaspersky. Nice tutorial!

  6. Aylen says:

    I used the remover from and it worked great

  7. The first day of school is tough for everybody-new class, new teacher,
    new everything. So the result is, your hair will
    be always flying around and be extra puffy or frizzy. Yet
    his impact continues to be felt in many areas of life, with many other things being
    named after him, besides the Caesar haircut; including the calendar month
    of July (after his first name, Julius), and the
    maternity procedure known as Caesarian section; to recall but a few
    of the many things named after this Roman ruler.

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!