Author Topic: Win32:Sality-AI  (Read 4493 times)

0 Members and 4 Guests are viewing this topic.

CaptCom

  • Guest
Win32:Sality-AI
« on: July 07, 2007, 05:36:55 AM »
Hi all,

Please I need help to get rid of this virus I catched for an unknown way.
File: C:\WINDOWS\system32\vcdgcw32.dll
Virus: Win32:Sality-AI
Type: Virus/Ver ( worm )
VPS Version: 000754-4, 2007-07-06

I tried to delete it, repared it, put it in quarantine, etc... it always ome back each time I reboot.

Please help me!!!

Thank you

mauserme

  • Guest
Re: Win32:Sality-AI
« Reply #1 on: July 07, 2007, 07:21:59 AM »
Try an avast! boot scan, making sure to use the clean (or repair) option on any detections.

CaptCom

  • Guest
Re: Win32:Sality-AI
« Reply #2 on: July 07, 2007, 07:43:38 AM »
Thanks I will try that.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Win32:Sality-AI
« Reply #3 on: July 07, 2007, 02:09:08 PM »
it always ome back each time I reboot.
If a virus is replicant (coming and coming again), you could follow the general cleaning procedure:

1. Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it's not available in Windows 2k. After boot you can enable System Restore again after step 3).

2. Clean your temporary files. You can use CleanUp or the Windows Advanced Care features for that.

3. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).

4. It will be good if you download, install, update and run AVG Antispyware. Some users recommend SUPERantispyware, Spyware Terminator and/or a-squared (take care about false positives).
If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.

5. If you still detecting any strange behavior or even you're sure you're not clean, maybe it will be good to test your machine with anti-rootkit applications. I suggest AVG, Panda and/or F-Secure BlackLight.

6. Also, if you still detecting strange behaviors or you want to be sure you're clean, maybe making a HijackThis log to post here and, specially, scan and submit to on-line analysis the RunScanner log would help to identify the problem and the solution.

7. After you're clean, use the immunization of SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.

8. Finally, when you're clean, check for insecure applications with Secunia Software Inspector to update insecure applications and avoid reinfection.
The best things in life are free.

CaptCom

  • Guest
Re: Win32:Sality-AI
« Reply #4 on: July 07, 2007, 04:32:40 PM »
Thanks Tech. I will try that because the first solution failed. The Cleaner never found it.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Win32:Sality-AI
« Reply #5 on: July 07, 2007, 04:40:16 PM »
The Cleaner never found it.
avast The Cleaner?
It's not a full antivirus, just a removal tool. It won't detect more than avast antivirus, on contrary, will detect just few cleanable malwares.
The best things in life are free.

CaptCom

  • Guest
Re: Win32:Sality-AI
« Reply #6 on: July 07, 2007, 04:44:47 PM »
I saw that. The antivirus ( Avast ) found it and before I do anything I start the cleaner.
I will do what you suggested ;)

mauserme

  • Guest
Re: Win32:Sality-AI
« Reply #7 on: July 07, 2007, 08:14:04 PM »
Sality is a file infector of exe's that also drops a backdoor in the windows folder.  The backdoor is safe to delete, but deleting the infected exe's may cause problems.  These should be cleaned instead, and if avast! isn't successfull then maybe an online scan will help.

Are there more files that just C:\WINDOWS\system32\vcdgcw32.dll detected?

CaptCom

  • Guest
Re: Win32:Sality-AI
« Reply #8 on: July 07, 2007, 08:49:24 PM »
Thanks for your answer.

So far all I tried failed.

Quote
Are there more files that just C:\WINDOWS\system32\vcdgcw32.dll detected?

I don't think so but I'm not 100% sure because Avast found it when I boot and even if I try to delete it, it comes back another time with the same warning message and I have to delete it again. Then its ok.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Win32:Sality-AI
« Reply #9 on: July 08, 2007, 01:10:37 AM »
I don't think so but I'm not 100% sure because Avast found it when I boot and even if I try to delete it, it comes back another time with the same warning message and I have to delete it again.
Did you try the steps I've posted on #3 just above?
The best things in life are free.