Virus Characteristics
| File Property | Property Value |
| FileName | !itw#6.exe |
| McAfee Artemis | Artemis!8b5b1bb2e877
|
| McAfee Detection | W32/Autorun.worm.fn |
| Length | 72,704 bytes |
| CRC | 24022629 |
| MD5 | 8B5B1BB2E8774055C5CA103423850A3C
|
| SHA1 | 682F3BD5BAE735DFB8081A8AFE98CEBBF689EA24
|
Other Common Detection Aliases
| Company Name | Detection Name |
| ahnlab | Win32/Palevo.worm.72704.D
|
| avast | Win32:Rimecud-B [Wrm]
|
| AVG (GriSoft) | Worm/Generic.ZNB |
| Avira | TR/Crypt.ZPACK.Gen |
| BitDefender | Trojan.Generic.1835909
|
| Dr.Web | Win32.HLLW.Lime.18 |
| Eset | Win32/Peerfrag.BG |
| FortiNet | W32/Palevo.DLR!worm.p2p
|
| F-Prot | W32/Palevo.a |
| Kaspersky | P2P-Worm.Win32.Palevo.dlr
|
| microsoft | worm:win32/rimecud.b
|
| norman | autorun.zzv |
| panda | W32/P2PWorm.AL.worm |
| rising | Worm.Win32.Agent.avu
|
| Sophos | W32/Autorun-AIC |
| Symantec | W32.SillyFDC |
| Trend Micro | WORM_DROPPER.JBY |
| vba32 | P2P-Worm.Win32.Palevo.dlr
|
| V-Buster | Worm.P2P.Palevo.HX |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Modifies memory of other processes
| Critical |
Enumerates open windows
| Medium |
Enumerates running processes
| Medium |
Program often suspends itself
| Medium |
Uses shared memory of other processes
| Low |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\!itw#6.exe
The following files have been added to the system:
c:\recycler\s-1-5-21-6437343670-8511773086-460514716-2025c:\recycler\s-1-5-21-6437343670-8511773086-460514716-2025\desktop.inic:\recycler\s-1-5-21-6437343670-8511773086-460514716-2025\winmap32.exe
The following registry elements have been changed:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows nt\currentversion\winlogon\- taskman = c:\recycler\s-1-5-21-6437343670-8511773086-460514716-2025
\winmap32.exe