Several weeks ago my computer was infected by WS32 Sality computer virus.
The virus attacks the computer registry system and removed all important .exe files such as antivirus, registry cleaner and games attached to the desk top.
The virus also disable the computer safe mode and blocked all of the browser available for visiting free antivirus and free registry cleaner sites. It also disable the previous AVG which was the computer antivirus from updating.
I tried installing Norton antivirus and the result was the same, the virus will immediately removed the .exe file.
So, I tried different approach, which was by visiting an antivirus site trough third party sites, which was tucow.com,....it worked and I was able to download an Avira antivirus.
Immediately I ran the antivirus after downloading it and was able to detect the location of the virus, which was attached to the computer restore system. I noticed the 1410 files detected with the virus were residing in System Volume Information file folder which was located in the System Restore.
How to open the System Volume Information folder :
- Right click “Start – explore – tools – folder options – view – show hidden files and folders – (unchecked)hide protected operating system files”
- Right click “system volume information – options – security – add (in order for you to open system volume information folder you have to add your PC user name in the “Group and user names” window) – apply – ok
- Now you can click and open the system volume folder
Then go to System restore section in your window xp and turn it off.
Then you download a file Unlocker program (Google it up) and run it after the download is complete. It is a free small file which enable you to forcefully delete stubborn infected files.
Now again open the System Volume Information folder by clicking it, you will find many folders and inside the folder contain back up system information files usually with a running number eg. A1002008 – A1002020. If you have an Avira anti personal running, it will flash out sign which says that the file is infected.
Select the folder with virus in it and then delete it. If it says “the file cannot be deleted because it is used by other program” , use the file unlocker program to forcefully deleting the folder.
After successful deleting all the infected files, run the Avira anti virus again.
Last go to”show and hidden……..” unchecked it, while the “hide protected operating……” checked it, don’t forget to turn on the system restore.
The viruses now all gone and your PC back to normal again.