Published Aug 26, 2010 | Updated Sep 15, 2017


Severe |Detected with Windows Defender Antivirus

Aliases: Trojan.Win32.Vilsel.amql (Kaspersky) W32/Spambot.gen.1126471 (Norman) Win32/Maazben!generic (CA) Win32/Sality.NBA (ESET) Virus.Win32.Sality (Ikarus) W32/Sality!inf (McAfee) Trojan.PSW.Win32.GameOL.udx (Rising AV) Troj/Salload-D (Sophos) TROJ_VILSEL.ZZ (Trend Micro)


Virus:Win32/Sality.gen!AT is a detection for a virus that spreads by infecting Windows executable files and by copying itself to removable and remote drives. It also terminates various security products, prevents certain Windows utilities from executing and attempts to download additional files from a predefined remote Web server.
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
For more information on antivirus software, see
Additional remediation instructions for Virus:Win32/Sality.gen!AT:
This threat may make lasting changes to a computer’s configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following article/s: 
Follow us