Remove Pexmor. Description and removal instructions

 
Title: Pexmor

Type: Worms
Severity scale:Pexmor severity is 49  (49 / 100)
 
Pexmor is an Internet worm that propagates by e-mail in messages with infected attachments. Once the user opens such an attachment, the parasite installs itself to the system and runs a spreading routine. Pexmor uses its own mail engine to send malicious letters to numerous addresses. It also prevents some installed software from running on Windows startup. Although the worm doesn't carries any destructive payload, its activity may severely degrade overall system performance and Internet connection speed. Pexomor secretly runs on every Windows startup or whenever the user composes an e-mail message.


Pexmor properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Pexmor removal:

remover for Pexmor

Pexmor manual removal:

Kill processes:
lsass.exe, msmsgs.exe, svchost.exe, winword.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\NortonAntivirus=%Windir%\Temp\officehost.vbs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OfficeQuickAccess=%Windir%\Temp\officehost.vbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NortonAntivirus=%Windir%\Temp\lsass.exe
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Compose Use Stationery=1
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Stationery Name=%Windir%\Temp\folder.htm
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Wide Stationery Name=%Windir%\Temp\folder.htm
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Common\MailSettings\NewStationery
Delete files:
lsass.exe, msmsgs.exe, svchost.exe, winword.exe, sen.bat, sexo.pif, officehost.vbs, bailando.vbe, desktop.ini, folder.htm
Misc:
The infected bailando.vbe file comes attached to each Pexmor e-mail.

Exact file location:
lsass.exe, msmsgs.exe, svchost.exe, winword.exe, officehost.vbs, bailando.vbe, desktop.ini, folder.htm - C:\Windows\Temp or C:\Winnt\Temp
sen.bat, sexo.pif - C:\Windows\Drivers or C:\Winnt\Drivers

Other programs to remove Pexmor:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 17/09/05
Information updated: 17/09/05

Additional resources related to Pexmor:

Attention: If you know or you have a website or page about Pexmor removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Pexmor parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: