Worm

What is “P2P-Worm.Win32.Spear.e”?

Malware Removal

The P2P-Worm.Win32.Spear.e is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What P2P-Worm.Win32.Spear.e virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine P2P-Worm.Win32.Spear.e?


File Info:

name: 57F8B46432EC3F4FCFFB.mlw
path: /opt/CAPEv2/storage/binaries/f2029739f5d64edc0a0900bcaae5690ba5818d5e5d574a823c7087ffd30d4ab3
crc32: 56DB53A7
md5: 57f8b46432ec3f4fcffbbbffe05bc6b8
sha1: ab494c195f78a0036c824b30ab2f9b79639dacc8
sha256: f2029739f5d64edc0a0900bcaae5690ba5818d5e5d574a823c7087ffd30d4ab3
sha512: 6fbafc8e8dd4db725e778dcc0f2a3fe19b633b3a7befaeae14a93885cd9a458c878465175c603698a2411f76359fe1a9e8ca47b31eb028044d08593981797ba1
ssdeep: 192:PUzMCFc/kmLV+40Yqf1W6W9CiyiEK94Wsp/Kx7Ii2755wpwvaUOQIilC6Bm9vjsY:8o4+VFqw6WBEmzs4yiy5wSv/amm9bsY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F331853E6E2C4B6E120EDFD6E35B059EB7276292C56045AFCEE6DCC8B1A150091C24B
sha3_384: f309245fd9ddd703a92888c264d57eb1e49d434e584d3d2f6425fd606cec5138d23969756ad3f54fc9c90ebb498c82f8
ep_bytes: 558bec83c4f0535633c08945f0b80839
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

P2P-Worm.Win32.Spear.e also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Spear.E@mm
FireEyeGeneric.mg.57f8b46432ec3f4f
McAfeeArtemis!57F8B46432EC
Cylanceunsafe
SangforWorm.Win32.Spear.Vnj5
K7AntiVirusTrojan ( 004c0bd31 )
K7GWTrojan ( 004c0bd31 )
BitDefenderThetaAI:Packer.5AA9229E1E
SymantecW32.HLLW.Yoohoo
APEXMalicious
CynetMalicious (score: 100)
KasperskyP2P-Worm.Win32.Spear.e
BitDefenderWin32.Worm.Spear.E@mm
NANO-AntivirusTrojan.Win32.Spear.enxs
TencentWin32.Worm-P2P.Spear.Kcnw
EmsisoftWin32.Worm.Spear.E@mm (B)
F-SecureWorm.WORM/P2P.Spear
DrWebWin32.HLLW.Spear.17408
VIPREWin32.Worm.Spear.E@mm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminWorm/P2P.Spear.e
AviraWORM/P2P.Spear
Kingsoftmalware.kb.a.974
ArcabitWin32.Worm.Spear.EA8AF7
ViRobotWorm.Win32.A.P2P-Spear.17408
ZoneAlarmP2P-Worm.Win32.Spear.e
GDataWin32.Worm.Spear.E@mm
AhnLab-V3Dropper/Win32.Agent.C287746
ALYacWin32.Worm.Spear.E@mm
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
MalwarebytesMachineLearning/Anomalous.100%
RisingWorm.Yohoo!8.6141 (TFE:4:ZNeUqa6APSK)
IkarusWorm.P2P.Spear.Based
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Spear.E!worm.p2p
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove P2P-Worm.Win32.Spear.e?

P2P-Worm.Win32.Spear.e removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment