Anti-Worm.Palevo Icon

Anti-Worm.Palevo

Anti-Worm.Palevo can remove Worm.P2P.Palevo.DP

Anti-Worm.PalevoOverview

Anti-Worm.Palevo can remove Worm.P2P.Palevo.DP

Worm.P2P.Palevo.DP spreads via automatically IM spam. The message tricks the users into saving what seems to be
a .JPG file, which is, in effect, an executable concealing the malicious payload – Worm.P2P.Palevo.DP.
When the user tries to open the file, the malicious code is launched.

The worm creates four hidden files in the Windows folder:

%Windir%/infocard.exe
%Windir%/mds.sys
%Windir%/mdt.sys
%Windir%/winbrd.jpg

It then modifies some registry key to point to this files, in order to bypass the OS's firewall:
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/ [Firewall Administrating = "%Windir%/infocard.exe"]
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Terminal Server/Install/Software/Microsoft/Windows/CurrentVersion/Run/ [Firewall Administrating = "%Windir%/infocard.exe"]
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run/ [Firewall Administrating = "%Windir%/infocard.exe"]

NEW

Fixed some bugs.

Anti-Worm.PalevoInformation

Version
1.22
Date
05.06.10
License
Free
Language
English
File Size
194KB
Category
SubCategory
Operating Systems
Windows 7, Vista, XP
System Requirements
No additional system requirements.
Sober Removal Tool Icon
A cleaning tool that removes the Sober worm.
Free
More
SmadAV Icon
Protect your computer from viruses.
Free
RAV AntiVirus Desktop Icon
RAV AntiVirus Desktop protects the contents of your PC from malicious computer
Trial
Net Protector Icon
Total PC Protection : AntiVIRUS + Internet Security
Trial
Bugbear Removal Tool Icon
Detect and remove any variation of the Bugbear virus from your computer.
Free
RAV AntiVirus 8 Full Engine Update Icon
RAV AntiVirus Full Update is the complete database of virus signatures.
Free
ESET NOD32 Antivirus (64-bit) Icon
Protect your system and files from virus and spyware.
Demo
iReset Icon
A tool to reset system/hidden files/folders so you can view/access them normally
Free
PyLoris Icon
A testing tool for web server DoS vulnerabilites.
Free
More