Malware
Sality virus explained: file infection, alerts and safe recovery
What the Sality file-infecting virus alert means, how Windows executables can be affected, and safe recovery steps that do not promise every file can be repaired.

Sality is a family of Windows file-infecting viruses. Microsoft’s Malware Encyclopedia describes Virus:Win32/Sality as a family of polymorphic infectors that target Windows executable files, including .EXE and .SCR files. Some records also describe behavior such as disabling security software, changing security settings, downloading other files or deleting files. A Sality alert should therefore be treated seriously, but the detection name alone does not prove that every file on a device is infected, that the family is currently widespread, or that an altered executable can be repaired. If you have just seen the alert, do not open the flagged file or connect unscanned removable media. Use an up-to-date security scan, keep potentially affected files isolated, and ask your organization’s IT or incident-response team for help where the device is business-managed.
What is the Sality virus?
Sality is not one single file or one dated outbreak. It is a malware family whose members infect Windows executable files. “File-infecting” means the malware’s code is associated with an existing executable rather than being limited to a separate downloaded program. “Polymorphic” means family members can change aspects of their form, which can make detection and analysis more difficult.
Microsoft’s family-level entry says that Sality threats may stop security software, steal sensitive information, download and run other files, delete security-related files, and lower a PC’s security settings. Those are capabilities described for the family; they are not proof that every sample or every alert performed every action.
The name may appear in several formats. A product can show a family-level label such as Virus:Win32/Sality, a variant label such as Virus:Win32/Sality.AU, or a generic detection such as Virus:Win32/Sality.gen!AT. These labels should not automatically be counted as separate viruses or separate current campaigns.
How does Sality infect files?
The core risk is modification of Windows executable files, especially files with .EXE or .SCR extensions. A modified executable may fail to run, behave unexpectedly, or spread the infection when launched on another Windows computer. Some Microsoft variant records also describe copying to removable or remote drives and association with a Sality worm record.
That does not mean every .EXE on a device is infected, nor does it mean that a USB drive is the only possible source. The safe assumption after a credible detection is that executable files and connected media need careful scanning before they are opened or shared.
Do not test a suspected sample by running it, renaming it, uploading it to an unapproved service, or disabling antivirus protection. If a file is needed for work, obtain a clean replacement from the software publisher or a known-good organizational repository instead of trying to make the flagged copy run.
What does a Sality alert mean?
A Sality alert means a security product has matched a file or activity to a Sality family or variant detection. Read the alert’s exact name, file path, action and status. “Quarantined” or “removed” is different from “allowed,” “failed,” “active,” or “needs attention.” The alert is a starting point for investigation, not a complete incident report.
A family name can also cover old detection records. Microsoft’s encyclopedia lists family and variant entries with publication or update records reaching back to the 2000s, including Sality variants documented in 2007–2011. Those record dates show when Microsoft documented or updated a detection; they do not establish present-day prevalence, a new outbreak, or the date your file became infected.
A detection can be attached to an infected executable, a related component, or a file that a security product believes is associated with the family. If the file is business-critical, preserve the alert details and ask IT or the security vendor to assess it rather than restoring it immediately.
Is Sality still active today?
The evidence reviewed for this page supports Sality’s classification and historical family/variant records. It does not support a current prevalence number, a claim of a 2026 outbreak, or a ranking such as “most dangerous.” Microsoft’s family page is an encyclopedia record published in 2008 and updated in 2017; related variant records have their own older dates. A current product detection can still require action even when the available public family documentation is old, but it should not be presented as proof of widespread current activity.
This distinction matters because security products retain detection names for older families and variants while definitions, detection logic and product interfaces change. Treat the device-specific alert and scan history as more relevant to the immediate case than an old “last updated” date on a family page.
How should I safely recover a Windows PC after a Sality alert?
Use this checklist. Menu names can vary by Windows version, edition, administrator policy and third-party security software, so follow the labels shown on the affected device rather than an old screenshot.
For broader first-hour decisions, see CYBERoinfo’s incident response first-hour checklist. The site’s malware guide provides the wider distinction between viruses, worms, Trojans and other malware.
- Stop opening suspicious files. Do not run the flagged executable or use it to test whether the alert was “real.”
- Reduce exposure. Disconnect from networks when practical, and do not attach removable or shared drives until they can be scanned. A business device should be isolated according to the organization’s incident plan.
- Record the alert. Note the detection name, path, time, action taken and whether the item was quarantined, removed, allowed or not remediated. Avoid deleting evidence that IT may need.
- Update protection before scanning. In Windows Security, open Virus & threat protection and use Protection updates to check for current security intelligence when the device can safely connect. Do not turn off real-time protection or create an exclusion for the flagged file.
- Run a deeper scan. In Windows Security > Virus & threat protection, choose Scan options and run a Full scan. Microsoft also provides Microsoft Defender Antivirus (offline scan), which restarts the PC and scans outside the normal Windows environment; save work first and expect the restart.
- Use a current second opinion if needed. Microsoft Safety Scanner is a manually triggered tool, not a replacement for real-time protection. Download a fresh copy for each use because the tool expires 10 days after download, then review its on-screen result and log.
- Do not assume infected executables were repaired. Antivirus may quarantine, delete, or sometimes clean a file, but an altered executable can remain unusable or untrustworthy. Replace software files from a known-good source. Restore personal or business data only from a backup that predates the infection and was stored separately or has trustworthy version history.
- Check for persistence or repeat detections. If the same threat returns after a restart or scan, stop normal use and escalate. Repeated detection can indicate an unclean component, a reintroduced file, or an affected drive or share.
- Protect accounts after containment. From a known-clean device, change passwords that may have been used on the affected computer, starting with email, administrator and financial accounts. Review sign-in activity and revoke sessions where the service supports it.
- Escalate when recovery is uncertain. A managed computer, a machine with disabled security controls, multiple infected executables, suspected data theft, or a failed offline scan needs professional assessment. Resetting or reinstalling Windows may be safer than attempting ad-hoc repairs, but preserve required data and evidence first.
Can antivirus repair Sality-infected files?
Sometimes a security product can clean or remove a detected file, but there is no universal promise that it can repair every altered executable. File infection may change the program’s contents, integrity or ability to run. A “clean” result can mean the threat was quarantined or removed; it does not necessarily mean the original program was restored exactly.
For applications, reinstall from the publisher or an organization-approved package. For documents and other non-executable data, check them with current security software and restore from a clean, independently stored backup if there is any doubt. Do not restore an entire drive image or copy executable files back until the recovery source and device have been assessed.
What should businesses do differently?
Organizations should treat a Sality detection as a possible endpoint and removable-media issue, not just a single-file cleanup. Isolate the endpoint under the incident-response plan, notify the security team, identify connected shares and removable media, and preserve relevant alert and scan records. Review whether executable files were copied to shared locations and whether credentials were used from the device.
Do not let an employee continue using a detected machine for privileged administration or sensitive access while scans are incomplete. The right action may include rebuilding the endpoint, rotating credentials, and validating software inventories rather than attempting to repair each infected file. The exact scope should be based on logs and the organization’s evidence-handling process.
Sality virus: evidence limits and terminology
- Family versus variant: Virus:Win32/Sality is the family-level Microsoft label. Suffixes such as .AU, .AH and generic labels identify particular records or detection groupings; they are not automatically separate pages or separate current outbreaks.
- Historical record versus current prevalence: Microsoft’s dated encyclopedia pages document detections and capabilities. They do not provide a current infection count or prove that Sality is presently widespread.
- Capability versus observed action: A family description can list possible behaviors. It does not prove that the specific file on your device executed every listed behavior.
- Detection versus recovery: A detection tells you to investigate and contain. It does not guarantee that a file can be repaired or that one scan proves the whole device is clean.
- Virus versus other malware: Sality is a file-infecting virus family. It should not be used as a label for every malware alert, worm, Trojan or ransomware event.
Frequently asked questions
Question: Is Sality a worm or a virus?
The primary Microsoft family record used here classifies Virus:Win32/Sality as a family of file infectors. Some variant records also describe removable-drive or remote-drive spreading and a related worm-named detection. Use the exact product label and variant rather than treating “Sality” as one behavior in every case.
Question: Does a Sality alert mean my personal files were stolen?
No. Microsoft describes information-stealing as a possible family capability, but an alert alone does not establish that data was accessed or exfiltrated. Contain the device, preserve the alert details, and investigate account and network activity when the situation warrants it.
Question: Should I delete the flagged file?
Do not open it or manually move it to another computer. Let the security product quarantine or remove it where appropriate, and keep the alert record. If the file is important, replace it from a known-good source rather than restoring the flagged copy.
Question: What if the alert returns after a scan?
Stop normal use, avoid reconnecting removable or shared drives, and run the current offline scan option or an approved second-opinion scan. Repeated detections warrant IT or professional support because the source may be a hidden component, a reintroduced file, or another affected location.
Question: Is this page saying Sality is currently widespread?
No. The available evidence establishes a documented Microsoft malware family and older variant records, not a present prevalence estimate. A current alert still deserves prompt, careful handling on the affected device.
---
Decision checklist
- Record the exact security alert, file path, device, time and product status before taking action.
- Avoid running suspected malware or restoring quarantined content to test whether the alert is real.
- Use updated, reputable protection and follow the device owner’s incident-response process.
- Protect important accounts from a known-clean device if credentials may have been exposed.
- Escalate a managed-device infection, persistent detection or suspected data theft to qualified support.
Limitations
- An alert or family name alone does not confirm an infection or data theft on a particular device.
- Historical activity and vendor capability descriptions are not proof of a present-day outbreak or specific sample behavior.
- A scan or infrastructure disruption cannot guarantee that every related threat was removed.
- This educational article is not personalized incident-response or a device-specific diagnosis.
Evidence sources
- Microsoft — Microsoft Security Intelligence — Virus:Win32/Sality
- Microsoft — Microsoft Security Intelligence — Virus:Win32/Sality.AU
- Microsoft — Microsoft Security Intelligence — Sality threat search results, page 2
- Microsoft — Microsoft Support — How to start a scan for viruses or malware in Microsoft Defender
- Microsoft — Microsoft Learn — Microsoft Safety Scanner Download
- Microsoft — Microsoft Support — Troubleshoot problems with detecting and removing malware
- Microsoft — Microsoft Support — Virus and Threat Protection in the Windows Security App