Worm

Should I remove “UDS:P2P-Worm.Win32.Palevo.hydz”?

Malware Removal

The UDS:P2P-Worm.Win32.Palevo.hydz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:P2P-Worm.Win32.Palevo.hydz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:P2P-Worm.Win32.Palevo.hydz?


File Info:

name: 31C360B1FCDD0E93D0EA.mlw
path: /opt/CAPEv2/storage/binaries/91dc38e24f17ce7c92f0ab500b21674bccb0fc0c1bf22ecc256d2cb65dba0a0a
crc32: C6D3E168
md5: 31c360b1fcdd0e93d0eab7049957db6b
sha1: 19df2f81110b7b5434767858e3ffcd1960eea158
sha256: 91dc38e24f17ce7c92f0ab500b21674bccb0fc0c1bf22ecc256d2cb65dba0a0a
sha512: b067157238a93516341b112b171f3e8e3b11ce21c0c2ef206f7754813dbcf8e0666eff0eed58f6c97f3301dfd2eaff7ddea1f30aeb14d6012cf42c8222983d12
ssdeep: 6144:7tatPE5TxP8ev1zQBgexOdw6rpI9FsAC9:oPwTt8Cl+zGp64
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD647C1233E84865E5EA7E33CEB6A630D7FAE9759C33D66F0394420D4E3A904CB15366
sha3_384: 981f070bfba282a5a68cc2578fad028bd187ed124eeee574ee9256ce46286d4202061a5cfe09f109515a74c7ba401c1d
ep_bytes: 558bec6aff680091410068f450410064
timestamp: 2015-11-12 07:44:34

Version Info:

0: [No Data]

UDS:P2P-Worm.Win32.Palevo.hydz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.72250564
FireEyeGeneric.mg.31c360b1fcdd0e93
CAT-QuickHealBackdoor.Venik.25957
SkyhighBehavesLike.Win32.PWSGoft.fm
ALYacTrojan.GenericKD.72250564
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.72250564
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004d733b1 )
K7GWTrojan ( 004d733b1 )
BitDefenderThetaGen:NN.ZexaF.36804.tqX@aG5sdggj
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Farfli.BWM
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:P2P-Worm.Win32.Palevo.hydz
BitDefenderTrojan.GenericKD.72250564
NANO-AntivirusTrojan.Win32.Palevo.dyrclf
AvastWin32:BackdoorX-gen [Trj]
TencentP2P-Worm.Win32.Palevo.hb
EmsisoftTrojan.GenericKD.72250564 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader17.47296
ZillyaTrojan.Injector.Win32.335495
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fhjq
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.b.998
ArcabitTrojan.Generic.D44E74C4
ZoneAlarmUDS:P2P-Worm.Win32.Palevo.hydz
GDataWin32.Trojan.PSE.NQ4CG2
VaristW32/Palevo.AV.gen!Eldorado
AhnLab-V3Backdoor/Win.FDAJ.R607971
Acronissuspicious
McAfeeBackDoor-FDAJ!31C360B1FCDD
VBA32Worm.Palevo
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Venik!8.11E (TFE:5:RqOiOODmXTB)
YandexTrojan.GenAsa!p64uuvB0qys
IkarusTrojan.Win32.Farfli
FortinetW32/Farfli.BTY!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove UDS:P2P-Worm.Win32.Palevo.hydz?

UDS:P2P-Worm.Win32.Palevo.hydz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment