WORM_PALEVO.GEN

 Analysis by: Roland Marco Dela Paz

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Worm

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

NOTES:
This is the Trend Micro detection for suspicious files that manifest behavior and characteristics similar to WORM_PALEVO variants.

WORM_PALEVO variants are known to propagate via peer-to-peer (P2P) networks, MSN Messenger and removable drives. They are capable receiving commands from a remote malicious user, which may involve performing Denial of Service (DOS) attacks, information-stealing, and downloading possibly malicious files, among others.

If your Trend Micro product detects a file under this detection name, do not execute the file. Delete it immediately especially if it came from an untrusted or an unknown source (e.g., a web site of doubtful nature).

However, if you have reason to believe that the detected file is non-malicious, you can submit a sample for analysis. Detailed analysis will be done on submitted samples, and corresponding removal instructions will be provided, if necessary.