Worm

Worm.P2P.Palevo.W removal

Malware Removal

The Worm.P2P.Palevo.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.P2P.Palevo.W virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
butterfly.BigMoney.biz
butterfly.sinip.es

How to determine Worm.P2P.Palevo.W?


File Info:

crc32: E2CE8A9D
md5: 3bb1334f8ea3fc9e98417a34886e31e0
name: 3BB1334F8EA3FC9E98417A34886E31E0.mlw
sha1: c30a56885618e19e36891e8cb68d2b949ede616c
sha256: 45fae4e698c625a807f014f401fa0f81611776765bac5ea74146739d34f2f779
sha512: f008329f97c8d476ddb07114c98c93df33910e1036c1dcfa1e30fac3cc48310c6f83b49947db261667d969d999966036cb1a3e342f053982d20791c743c73f4c
ssdeep: 1536:usUNW5K/x5RbXSNq5miktilWlmF1g+roSzXDBEUGOloMcP/B25nINgg:yNWwZP2N2/8+rocNBlY25
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm.P2P.Palevo.W also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004c05641 )
LionicWorm.Win32.Palevo.ljZ5
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Lime.52
MicroWorld-eScanWorm.P2P.Palevo.W
CAT-QuickHealWorm.Silly
ALYacWorm.P2P.Palevo.W
MalwarebytesWorm.Palevo
ZillyaWorm.Palevo.Win32.116307
SangforWorm.Win32.Palevo.jvq
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaWorm:Win32/Palevo.77cf76eb
K7GWTrojan ( 004c05641 )
Cybereasonmalicious.f8ea3f
BaiduWin32.Worm.Peerfrag.an
CyrenW32/Palevo.C.gen!Eldorado
SymantecW32.Pilleuz
ESET-NOD32Win32/Peerfrag.DZ
APEXMalicious
AvastWin32:Palevo-C [Trj]
ClamAVWin.Worm.Palevo-34516
KasperskyP2P-Worm.Win32.Palevo.jvq
BitDefenderWorm.P2P.Palevo.W
NANO-AntivirusTrojan.Win32.Palevo.dpmsex
ViRobotWorm.Win32.P2P-Palevo.116224.E
TencentWin32.Worm-p2p.Palevo.Lnen
Ad-AwareWorm.P2P.Palevo.W
SophosML/PE-A + W32/Rimecud-A
ComodoP2PWorm.Win32.Palevo.jvq0@1cu8ea
BitDefenderThetaAI:Packer.CF6C4C831E
VIPREWorm.Win32.Rimecud.b (v)
TrendMicroWORM_PALEVO.SMU
McAfee-GW-EditionPWS-Zbot.i
FireEyeGeneric.mg.3bb1334f8ea3fc9e
EmsisoftWorm.P2P.Palevo.W (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Palevo.ebq
WebrootW32.Malware.Gen
AviraWORM/Palevo.jvq
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVMH008.a.(kcloud)
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
GDataWorm.P2P.Palevo.W
TACHYONWorm/W32.Palevo.116224.AJ
AhnLab-V3Win32/Boaxxe.worm.Gen
McAfeePWS-Zbot.i
MAXmalware (ai score=82)
VBA32Trojan-Injector.Win32.SysDate.9251042
PandaW32/ButterflyBot.A
TrendMicro-HouseCallWORM_PALEVO.SMU
RisingWorm.Palevo!1.99B2 (CLASSIC)
YandexWorm.Palevo.Gen!Pac.4
IkarusP2P-Worm.Win32.Palevo
FortinetW32/Kryptik.ANN!tr
AVGWin32:Palevo-C [Trj]
Paloaltogeneric.ml

How to remove Worm.P2P.Palevo.W?

Worm.P2P.Palevo.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment