English
Romana
Home
|
Contact
|
Feedback
SEARCH
Security Development
Company
Careers
Press Center
Virus Info
Security News
Virus Glossary
About Malware
VDF History
External Links
Solutions
Products
Alerts Panel
Support
Register
Worm/Palevo.AC - Worm
See also
Summary
Full description
Virus:
Worm/Palevo.AC
Date discovered:
15/02/2010
Type:
Worm
In the wild:
Yes
Reported Infections:
Low
Distribution Potential:
Low
Damage Potential:
Low to medium
Static file:
Yes
File size:
184.832 Bytes
MD5 checksum:
c4358c82de2bedfc1b421024a3c68f74
IVDF version:
7.10.04.71
General
Method of propagation:
• Autorun feature
Platforms / OS:
• Windows 2000
• Windows XP
• Windows 2003
Side effects:
• Drops malicious files
• Registry modification
Files
It copies itself to the following location:
• %recycle bin%\
%CLSID%
\nissan.exe
The following files are created:
– %recycle bin%\
%drive%
\Desktop.ini
–
%drive%
\autorun.inf This is a non malicious text file with the following content:
•
%code that runs malware%
Registry
One of the following values is added in order to run the process after reboot:
– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
• "Taskman"="%recycle bin%\
%CLSID%
\nissan.exe"
The following registry key is changed:
– [HKEY_USERS\S-1-5-21-2025429265-1425521274-839522115-1003\Software\
Microsoft\Internet Explorer\Toolbar]
New value:
• "Locked"=dword:0x00000000
Backdoor
The following ports are opened:
– pica.ba**********.ru on UDP port 34000
– sandra.pr**********.com on UDP port 34000
– l33t.br**********.net on UDP port 34000
Injection
– It injects itself as a thread into a process.
Process name:
• explorer.exe
File details
Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
See a brief description
here
.
Inserted by Petre Galan on Wed, 24 Feb 2010 16:07 (GMT+1)
Updated by Petre Galan on Thu, 25 Feb 2010 07:43 (GMT+1)
« Back
Print this page
Latest News
Avira survey shows 1 in 3 people think all websites pose security threat
Avira warns of Windows vulnerability
HEUR/HTML.Malware
TR/Crypt.XPACK.Gen3
TR/Crypt.XPACK.Gen2
W32/Sality.Y
Java/Agent.M.1
TR/Renos.E
Worm/Palevo.aemi
Worm/Palevo.akyt
Worm/Palevo.zed
TR/Kryptik.FU
Download here
© 2010 Avira Soft SRL
Privacy
|
Site terms
|
Copyright
|
Site map