Threat Database Worms W32/Palevo.gen.a

W32/Palevo.gen.a

By GoldSparrow in Worms

W32/Palevo.gen.a is a worm that targets computers with Windows Operating systems. W32/Palevo.gen.a propagates via removable drives and can also be obtained from file-sharing or peer-to-peer networks. Once inside a PC, W32/Palevo.gen.a will create a start-up registry entry. W32/Palevo.gen.a connects to a remote server and downloads other harmful programs onto an infected PC. W32/Palevo.gen.a may also steal saved usernames and passwords by accessing certain web browser related files.

File System Details

W32/Palevo.gen.a may create the following file(s):
# File Name Detections
1. [Removable Drive]:\SVETICEE\severinchich.exe
2. %UserProfile%\csrss.exe
3. [Removable Drive]:\aurorun.inf

Registry Details

W32/Palevo.gen.a may create the following registry entry or registry entries:
"Taskman:" = "%userprofile%\csrss.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\]

Trending

Most Viewed

Loading...