Knowledge Base

Support

Removing the PE_Sality.M, PE_Sality.EK, PE_Sality.EN, PE_Sality.EM, PE_Sality.BU, PE_Sality.AZ, PE_Sality.BA or PE_Sality.RL virus from your computers

Solution IDLast Updated
1037686Date : 2012/02/9 Time: 1:57 AM (PST)


Product/VersionPlatform
OfficeScan - 10.0, 10.5; ServerProtect for Microsoft Windows/Novell Netware - 5.7, 5.8; Trend Micro AntiVirus plus AntiSpyware - 2008, 2009, 2010; Trend Micro Internet Security - 2008, 2009, 2010; Trend Micro Internet Security Pro - 2008, 2009, 2010; Worry-Free Business Security Standard/Advanced - 5.1, 6.0, 7
Windows - 2000 Server, 2003 Standard Server Edition, XP Home

Problem Description

Virus information on the following can be found at the Trend Micro Virus Encyclopedia:

PE_Sality.M

PE_Sality.EK

PE_Sality.EN

PE_Sality.EM

PE_Sality.BU

PE_Sality.AZ

PE_Sality.BA

PE_Sality.RL

Solution

Important: Test this solution first in a selected group of computers BEFORE rolling it out to all of the infected computers.

 

Please do the following:

 

1.

Download the PE_Sality fixtool.

 

   

2.

Download the latest Controlled Pattern Release (CPR).

 

   

3.

Download the latest Spyware Detection and Cleanup (Trend Micro Anti-Spyware) - Ssapiptn.Da5.

 

   

4.

Extract the PE_Sality fixtool to a temporary directory (i.e. c:\test).

 

   

5.

Extract the CPR (lpt$vpn.xxx) to c:\test\system\sysclean.

 

   

6.

Extract the spyware pattern (ssapiptn.DA5) to c:\test\system\sysclean.

 

   

7.

Using GPO or any 3rd party deployment tools (i.e. SMS, BigFix, Altiris), copy the extracted files (mentioned in item # 4-6) into the c:\temp folder of the infected computer(s).

 

   

8. 

Using GPO or any 3rd party deployment tools (i.e. SMS, BigFix, Altiris), run c:\temp\fix.bat.

 

   

 

Note: This script file will execute tsc.com and sysclean.com to remove PE_SALITY infection.

 

   
9.

Restart the computer. System reboot is required to completely restore and remove the malware entries and modifications.

 

   

 

Note: This new and improved fixtool does NOT require a boot in safe mode to clean PE_Sality.

 

   
10. 

Make sure that your Trend Micro product is up and running. If needed, please reinstall OfficeScan.

   

 

 


Rate this Solution
Did this article help you?  
 
Please provide your comments to help us improve this solution.

 
  *This form is an automated system. General questions, technical, sales and product-related issues submitted through this form will not be answered.
 
 

Connect with us on