Worm

Worm.Palevo.16785 (file analysis)

Malware Removal

The Worm.Palevo.16785 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Palevo.16785 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:568
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Worm.Palevo.16785?


File Info:

crc32: 5C65119E
md5: fd6e20ee918918201356cf32b683d766
name: FD6E20EE918918201356CF32B683D766.mlw
sha1: 34fe29da2fedb4e2d66c00fce8c11a99423f54b1
sha256: 16e9371f38b53d612fba56eafc1ebc87622e302c5db16de64549bdb0e4dcf2de
sha512: 135ddf18f5d195593da56853359a8fe787b32d4d8b1da45d3da78cad3a827eab51051b7939f4e02183e957ba6ee30f29bc4f90585c49b3c09f59d064820a7f4e
ssdeep: 6144:1B8pRFGJSRSs7/62JE4FgORTy2wCB20E/wcFwDKMiD9HRt:1CpawD69H/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: DXVM
FileVersion: 1.1.1.11
Comments:
ProductName: x590dx5236x7c98x8d34
ProductVersion: 1.1.1.1
FileDescription: x590dx5236x7c98x8d34
Translation: 0x0804 0x04b0

Worm.Palevo.16785 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005328801 )
Elasticmalicious (high confidence)
CAT-QuickHealWorm.Palevo.16785
CylanceUnsafe
K7GWTrojan ( 005328801 )
Cybereasonmalicious.a2fedb
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
SophosGeneric ML PUA (PUA)
ComodoApplication.Win32.BlackMoon.AI@822vgj
BitDefenderThetaGen:NN.ZexaF.34608.pq0@amK16unb
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.fd6e20ee91891820
SentinelOneStatic AI – Suspicious PE
PandaTrj/GdSda.A
RisingTrojan.Injector!1.A1C3 (CLASSIC)
IkarusAdWare.Win32.BlackMoon
FortinetW32/Agent.WP!tr

How to remove Worm.Palevo.16785?

Worm.Palevo.16785 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment