PE_PAGIPEF.AD-O infects all executable files

Dec 27, 2007 19:26 GMT  ·  By

We've seen similar infections in the past, but since this is a new one, it may bypass your antivirus and reach the files stored on your drives. PE_PAGIPEF.AD-O is that kind of infection that targets your executable files, so that some of them may become unusable because the file infector adds its codes at the beginning and at the end of the target file, security vendor Trend Micro wrote in an advisory published a few days ago. Windows 98, ME, NT, 2000, XP and Server 2003, they may be all infected with PE_PAGIPEF.AD-O.

And now, the most important two questions: how do we get infected and how do we remove the virus? Your computer can be easily cleaned with an up-to-date antivirus, but there are several ways to get infected. Trend Micro informs that PE_PAGIPEF.AD-O can be dropped on your system by unknowingly downloading it or can be also deployed by another infection. Simple as that!

It's hard to discover the file infector on your computer, because it is pretty smart and attempts to hide its content by using the name of legitimate Windows files, Trend Micro noted. Moreover, it attempts to copy itself on every clean removable drive, just like a spreading method, which proved us several times that it can be pretty successful.

"It drops files/components detected by Trend Micro as TROJ_PAGIPEF.AD. As a result, malicious routines of the dropped Trojan are also exhibited on the affected system", the security company explained in the advisory. "Infected files are detected by Trend Micro as PE_PAGIPEF.AD."

There's not much to do in order to protect yourself of the file infector. Just remember to apply the latest definitions for your security application and avoid visiting suspect websites that may attempt to deploy the infection!