Malware

What is “Palevo.6”?

Malware Removal

The Palevo.6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Palevo.6 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

redirector.gvt1.com
r3—sn-4g5ednsd.gvt1.com
update.googleapis.com

How to determine Palevo.6?


File Info:

crc32: 81659174
md5: 06bfedb7cd415572beb5d785e795f602
name: 06BFEDB7CD415572BEB5D785E795F602.mlw
sha1: 31ae97850397e3e98589eab7235e690f84239b93
sha256: d6fe2412fff8dac9dd2c5e4fd9eb6ffa0413f47d531a8f93de22ebdd28b522ff
sha512: 94d9dfb78394622d7a932e0c55f80695b66345fa29576369afaee6a931799db3859641248dbf16eab33a99b3d269ba8ef2c5b6b6796693c22fe1a10a80b9111b
ssdeep: 768:x82XRyHJ6+tXDL3cmbJhoWYY2TMF+Mms4btL1UVfWlXN6YhXKoJS4PD:fXgp6Is4tYY6MF+M54ZmVm/L
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Palevo.6 also known as:

BkavW32.RansomTO.Fam.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Palevo.6
FireEyeGeneric.mg.06bfedb7cd415572
CAT-QuickHealTrojanDropper.Wlock.AA6
ALYacGen:Variant.Palevo.6
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001ed2f11 )
BitDefenderGen:Variant.Palevo.6
K7GWTrojan ( 001ed2f11 )
CyrenW32/Ransom.E.gen!Eldorado
SymantecTrojan.Ransomlock
TotalDefenseWin32/RansomLockscreen.AJ
AvastWin32:Malware-gen
ClamAVWin.Trojan.Hmblocker-620
KasperskyTrojan-Ransom.Win32.HmBlocker.alu
AlibabaRansom:Win32/HmBlocker.7e453428
NANO-AntivirusTrojan.Win32.Winlock.bsinq
Ad-AwareGen:Variant.Palevo.6
EmsisoftGen:Variant.Palevo.6 (B)
ComodoTrojWare.Win32.Trojan.Ransom.~B@465pcw
F-SecureTrojan.TR/Spy.69120.psb
DrWebTrojan.Winlock.4205
ZillyaTrojan.HmBlocker.Win32.4257
McAfee-GW-EditionRansom-AA
SophosML/PE-A + Mal/Zbot-GO
IkarusTrojan-Ransom.HmBlocker
JiangminTrojan/HmBlocker.fd
WebrootW32.Trafog.Gen
AviraTR/Spy.69120.psb
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Ransom]/Win32.HmBlocker
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Trafog!rts
ArcabitTrojan.Palevo.6
ZoneAlarmTrojan-Ransom.Win32.HmBlocker.alu
GDataGen:Variant.Palevo.6
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HmBlocker.R2314
McAfeeArtemis!06BFEDB7CD41
MAXmalware (ai score=100)
VBA32OScope.Trojan.PornoBlocker.Restarter
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
APEXMalicious
ESET-NOD32a variant of Win32/LockScreen.ABE
TencentWin32.Trojan.Hmblocker.Glz
YandexTrojan.GenAsa!AZtTaYFYKmA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7175209.susgen
FortinetW32/Kryptik.19500!tr
BitDefenderThetaAI:Packer.46D0429A1F
AVGWin32:Malware-gen
Qihoo-360Malware.Radar01.Gen

How to remove Palevo.6?

Palevo.6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment