Home Malware Programs Worms Peerload

Peerload

Posted: March 28, 2006

Peerload is an Internet worm that spreads through many file sharing networks such as Kazaa, iMesh or eMule. It comes in files with meaningful names that trick the user into downloading and opening them.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winlogin.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinlogin=%System%winlogin.exe
Loading...