Modified by: Abraham Latimer Camba

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: File infector

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This is the Trend Micro detection for files that were incorrectly infected by PE_SALITY variants.

Files detected as PE_SALITY.DAM have damaged infection caused by the malware file itself. This damage infection makes the virus and host file un-executable and also the host unrestorable. These files cannot infect other files but must be replaced with clean backup copies.

  TECHNICAL DETAILS

File Size: Varies
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 24 Apr 2012

NOTES:

This is the Trend Micro detection for files that were incorrectly infected by PE_SALITY variants.

Files detected as PE_SALITY.DAM have damaged infection caused by the malware file itself. This damage infection makes the virus and host file un-executable and also the host unrestorable. These files cannot infect other files but must be replaced with clean backup copies.

  SOLUTION

Minimum Scan Engine: 9.200
FIRST VSAPI PATTERN FILE: 9.242.03
FIRST VSAPI PATTERN DATE: 07 Jul 2012
VSAPI OPR PATTERN File: 9.243.00
VSAPI OPR PATTERN Date: 08 Jul 2012

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product to delete files detected as PE_SALITY.DAM. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.

Step 3

Restore deleted/modified files and/or registry entries from backup

*Note: Only Microsoft-related files/keys/values will be restored. If this malware/grayware also deleted registry keys/values related to programs that are not from Microsoft, please reinstall those programs on your computer.

     
    • Files detected as PE_SALITY.DAM


Did this description help? Tell us how we did.