PE_ZMISTx

 Analysis by: Karl Dominguez

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: File infector

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

86,016 bytes

File Type:

EXE

Memory Resident:

No

Initial Samples Received Date:

05 Dec 2012

NOTES:
This is a type of metamorphic virus that infects Win32 files. This virus disassembles the host file and integrates itself between the target file’s codes. This virus then rebuilds the codes that results into a new executable file.

  SOLUTION

Minimum Scan Engine:

8.900

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

Step 2

Identify and delete files detected as PE_ZMISTx using either the Startup Disk or Recovery Console

[ Learn More ]

Step 3

Restore files from backup Only Microsoft-related files will be restored. If this malware/grayware also deleted files related to programs that are not from Microsoft, please reinstall those programs on your computer again.


Did this description help? Tell us how we did.