You Are Here: Home » Worm.P2P.Palevo.FP Removal Tool

Worm.P2P.Palevo.FP Removal Tool

Read the entire article here: http://www.malwareci…indows-852.html

Description of Worm.P2P.Palevo.FP:

The Trojan spreads by spamming instant messages to contacts.

The malicious application copies itself in the operating system’s folder with the name “jusched.exe”, which is similar to a known programming language file. In order to start itself each time the operating systems runs the following registry values are added :

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with “Java developer Script Browse” which contains the path of the Trojan “%Windir%\jusched.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run : “Java developer Script Browse” with the value “%Windir%\jusched.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run : “Java developer Script Browse” with the value “%Windir%\jusched.exe”

It adds itself as an authorized application for the system’s firewall by adding a value into the following keyHKLM\​SYSTEM\​CurrentControlSet\​Services\​SharedAccess\​Parameters\​ FirewallPolicy\​StandardProfile\​AuthorizedApplications\​List .
It stops the Windows Automatic Updates Service, preventing the user from getting the necessary updates, including the ones that ensure the security of the system. It also tries to stop msmpsvc.exe which belongs to Microsoft Malware Protection Service.

It has the ability to send messages to contacts on the following instant messaging applications : Skype, Yahoo Messenger, AIM (AOL Instant Messenger).

Version Downloads Quota Files Add Date Updated
15281 0 1 April 12, 2012 April 12, 2012

Download

© 2012 Powered By Bitdefender

x
Loading...
Scroll to top