8 Step to Remove W32/Sality.AE

Sality is an computer virus which will infected any files with extension .exe .com and .scr , sality will using your default share folder to spreading in your network area beside that sality using old autorun.inf technique also to spreading. Your application will become a little bigger in size around 60kb-80kb after sality infected it.

No need to hide this virus was created in China /Taiwan it have some website list to update himself with new varian some of them pedmeo222nb.info, pzrk.ru, technican.w.interia.pl, www.kjwre9fqwieluoi.info and many more. Blocking this site list using hosts file might help you in short condition but after it updated you might in trouble again. like almost smart virus in the past sality have protection to keep him alive in their computer target. Sality will kill any application/website with some string list such as, avast! antivirus, F-Secure Gatekeeper Handler Starter, NOD32krn and many more. Sality will blocking your firewall, security notification, and also your computer safe mode.

The easiest way to know if you’re infected by this virus is you can’t boot your computer in safe mode or some application will not run when you open it. When this happen follow this step…..

Remove W32/Sality.AE

1. Disconnected your computer from the network.

2. Turn off “System Restore” when in cleaning process.

3. Turn off “Autorun” and “Default Share” download this file right click on it then choose install.

4. Kill active process in your computer backround and checking your startup file you can use hijackthis.

5. Scan with Norman Malware Cleaner please note because this virus will infected files with extesion .exe com and .scr you have to rename Norman_Malware_Cleaner.exe with new extension example Norman_Malware_Cleaner.cmd

please make sure you downloaded fresh new cleaner from norman official website and don’t run it before you change the extension or this cleaner will got infected first before he can eliminate sality.

6. For repair your computer to booting in safe mode please download this file and merge only one that same with your windows version.

7. Repair your registry using this file right click on it then choose install.

8. Reboot your computer and scan again with norman malware cleaner, after that reboot again to make sure your system clean.

Well done πŸ™‚

Similar Posts:


36 thoughts on “8 Step to Remove W32/Sality.AE”

  1. Hi,
    I have developed a website using html code and javascripting code and hosted the site asIntranet website for my organisation and placed the html files in C:Inetpubwwwroot path using IIS manger.Iam using windows 2003 server as my operating system.Now iam getting virus in this wwwroot file .If i stop this site in IIS virus is not effecting and if i again start the site in IIS virus is effecting in wwwroot folder iam using symantec antivirus software.When virus is effecting auomatically .exe, .cmd, files are getting created in this wwwroot folder.Kindly help me .

  2. I’m not sure this caused by virus sality, your computer/network might get infected by other virus. Try use norman malware cleaner to detect it.

  3. How I Was Able to Lose Thirty Póunds in Only a Month

    Hi, cool post. I have been thinking about this issue,so thanks for blogging. I’ll certainly be coming back to your posts. Keep up the good posts

  4. Thanks bro… I had my system affected with Winsality. Had tried may method and programmes before reaching here. Now I completely removed the virus following the steps mentioned here. You saved my life. It was my nightmare to back up all the hard drive of 500gb (!!) with loads of softwares and games.

    Kudos !! πŸ™‚

  5. Thanks Dude……you made my day !!!!! you saved my data that I thougt is gone forever…..its 200 GB……keep up the great work…excellent suggestion….thanks for everything.!!

  6. hi, my friend’s pc is also infected by the sality virus and i found your site and tried to follow your instructions in order to remove it but we could not follow your directions.. how exactly do we do step 3, that is turning off autorun and default share.. also, the file that is to be downlaoded in the step 3 is .inf when i click it, so how do i install?
    same also with the file to be installed in step 7.

    your help would be greatly appreciated.. πŸ™‚

  7. You can install all .inf files by right click on it then choose “install” hope this help solved your problem. I would like to recommended you to use AVIRA antivirus because last week ago I cleaned my client infected by sality/AC with AVIRA the result is good but all infected files can’t be repaired…

  8. i got the .inf already, thanks..

    another question though.. i am on step 4 now but i am not sure how to use the hijack this.. please help again.. perhaps you can assist me via YM?

  9. Read hijackthis help page? use hijackthis to remove virus process on startup, do a system scan then just check on virus startup process then click fix checked (if you confused ask some people in forum first to know which one you should removed), If virus is active in your computer background you have to kill it using task manager or 3rd tools that can help you to do that. Sorry I can’t assist you via YM. Fell free to tell me your problem in this comment box I will reply it as soon as possible.

  10. hello
    I followed your steps, but restorexp.reg (yes I am on windows XP) won’t work, like any other registration entries, in safe mode or normal mode, it’s the same.
    Please help

  11. Can you specify what won’t work? have you merged the reg code? do you have any bluetooth device installed?

  12. Hi, we came here after a good google search. Fine site you have here! Keep it up!

    NOTE FROM EDITOR: I have removed your website URL because it’s contains adult material.

  13. This is great info. I just absolutely love coming to your blog and checking what you have to say. Please never stop writing your bog. Your information and content is so great and I have been telling all my friends about it.

  14. eset, avg, kaspersky, an updated antivirus can repair .exe files infected with sality without deleted it. Of course if there new varian you may need to wait for update before you can repair it.

  15. Infected systdm files

    Hey, wht antivirus or progrm cn i use for REPAIRING my infected .exe system files and wormed software-installers .exe by the W32/Sality.AE?? Big thanks to your help. Kudos to this blog, big help

  16. im in step 3, the dialog box came out “another program is currently using this file” everytime i try to disable the autorun, default share and installing the hijackthis. pls help..


  17. sir,thankx for telling this.It is so sad,because i have already
    lost a lot of files and games and it was happend 2nd time.so i
    belives in you and your method.okey,next time i will try this!

  18. sir,after formatting for this viruse i had adobe flash player.
    my antiviruse software is showing that this viruse is in my
    c:\windows\system32\macromed\flash folder and the affected file is adobeflashupdate.exe.But this is totally hidden and i can’t remove it using my antiviruse software.so,i am thinking that this viruse is w32 sallity!help me!

  19. scan full your system with sality remover, you have to make sure your anti virus not infected or it will give false result. deleted all infected files and reinstall any lost programs back.

  20. sir,
    i have this problem one more time.i have used a full system scan method with kaspersky internet security2011 and it is saying that my computer is infected by 800 w32/sallity and 491 w32/katosha and is is spreading rapidly please give me the solution.

  21. if I’m on your position I will backup my important data then fully reinstall my operating system OR I will deleted all infected files and then reinstall missing files needed to run the programs.

  22. I pay a visit each day a few websites and information sites to read articles or
    reviews, however this website provides quality based content.

  23. good directory list

    My cousin indicated I’d personally maybe like this internet site. They seemed to be altogether correct. The following distribute genuinely made my morning. A person can not imagine simply the best way a great deal of moment I had put together invested with this information and facts! Thank you so much!

  24. delete WSReset.exe

    Heya are using WordPress for your site platform?

    I’m new to the blog world but I’m trying to get started and set up my own. Do you need any
    html coding knowledge to make your own blog? Any help
    would be really appreciated!

  25. Jan Berkowitz Page

    Does your site have a contact page? I’m having problems locating it but,
    I’d like to shoot you an e-mail. I’ve got some recommendations for
    your blog you might be interested in hearing. Either way, great site and I look forward to seeing it improve over time.

  26. I believe this is one of the most vital info for
    me. And i am happy studying your article. However wanna commentary on some normal things,
    The website style is ideal, the articles is in point of fact excellent :
    D. Excellent activity, cheers

  27. Do you mind if I quote a few of your posts as long as I provide credit and sources back to your website? My website is in the exact same area of interest as yours and my visitors would really benefit from some of the information you present here. Please let me know if this okay with you. Thanks!

Leave a Reply

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.