Solved! Use PWTJWE.EXE (Worm Palevo) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

PWTJWE.EXE – Worm Palevo removal

File MD5 Virus Alias
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Worm Palevo
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Trojan Artemis
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Trojan Generic
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Trojan Downloader
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Trojan Agent
PWTJWE.EXE 0cb7e1b6d564189f21ee77c15e3f23be Trojan Small

PWTJWE.EXE size: 40981 bytes
PWTJWE.EXE hash: 0CB7E1B6D564189F21EE77C15E3F23BE

Created files:

%WinDir%\pwtjwe.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\WinHelp32\Type: 10010000
HKLM\System\CurrentControlSet\Services\WinHelp32\Start: 02000000
HKLM\System\CurrentControlSet\Services\WinHelp32\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WinHelp32\DisplayName: Windows Help System
HKLM\System\CurrentControlSet\Services\WinHelp32\ImagePath: %WinDir%\pwtjwe.exe
HKLM\System\CurrentControlSet\Services\WinHelp32\Description: Windows Help System for X32 windows desktop

Detected by UnHackMe:

PWTJWE.EXE
Default location: %WinDir%\PWTJWE.EXE

Dropper information:
MD5: 0cb7e1b6d564189f21ee77c15e3f23be
File size: 40981 bytes

Leave a Reply