Worm

BScope.Worm.Chiviper (file analysis)

Malware Removal

The BScope.Worm.Chiviper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Worm.Chiviper virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine BScope.Worm.Chiviper?


File Info:

name: 998F26384A7D9140484C.mlw
path: /opt/CAPEv2/storage/binaries/44b86e355b25f901c942f6279ade0c021541bc311be6bc05c31e76fd64ef7d44
crc32: 9B598EC9
md5: 998f26384a7d9140484c78f9ebe93aec
sha1: 0ba048883e0bb688ce4cda2e2d149f8c5ed57ca9
sha256: 44b86e355b25f901c942f6279ade0c021541bc311be6bc05c31e76fd64ef7d44
sha512: 8c3300890dc38876e641702a470d300ab8954c7e5e191d0bfbf51b79b4c98bda53cfcf389cddbd93d2ab491764e4f6b08a1a0061b5db52ce49519e7f6ccbc486
ssdeep: 3072:SZd+0VQXJFMC1wIa6FlGYGL78RNwYJhbYKg/y7FChAgAJGtTBf3ejwDG:WK5+C1C688Ths7/yRKAfGtTBGjwDG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5443901E7C98297D4826DBC9F8B3232DF35ECA825381E17376446D899B788375A2773
sha3_384: baa45491b32dc1eebb75ed544dd4e69785b40c3dd1e7cfd5169f3e484f59983bacca7df4fe04e0b09954f05543a23255
ep_bytes: 558bec6aff6890bb4300680c55430064
timestamp: 2011-06-28 06:48:02

Version Info:

0: [No Data]

BScope.Worm.Chiviper also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Unruy.5
FireEyeGeneric.mg.998f26384a7d9140
CAT-QuickHealTrojanDownloader.Unruy.Q
ALYacGen:Variant.Unruy.5
CylanceUnsafe
K7AntiVirusTrojan ( 002589dc1 )
K7GWTrojan ( 002589dc1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Kryptik.ak
CyrenW32/Unruy.H.gen!Eldorado
SymantecW32.Unruy.A
ESET-NOD32a variant of Win32/Kryptik.AJLF
APEXMalicious
ClamAVWin.Malware.Unruy-9840577-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Unruy.5
NANO-AntivirusTrojan.Win32.Renamer.lloxl
AvastWin32:Unruy-B [Trj]
TencentMalware.Win32.Gencirc.10b0cfcb
Ad-AwareGen:Variant.Unruy.5
SophosML/PE-A + Mal/GamePSW-L
ComodoTrojWare.Win32.TrojanClicker.Cycler.CP@44jnry
DrWebBackDoor.Bandito.1290
TrendMicroTROJ_AGENT_056159.TOMB
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
EmsisoftGen:Variant.Unruy.5 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Unruy.5
JiangminBackdoor/Banito.zr
WebrootW32.Trojan.Gen
AviraTR/Dldr.Unruy.QA
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicrosoftTrojanDownloader:Win32/Unruy.Q
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Banito.C100677
Acronissuspicious
McAfeeGenericRXBH-AF!998F26384A7D
MAXmalware (ai score=85)
VBA32BScope.Worm.Chiviper
MalwarebytesMalware.AI.712848986
TrendMicro-HouseCallTROJ_AGENT_056159.TOMB
RisingTrojan.Kryptik!1.B59A (CLASSIC)
YandexTrojan.GenAsa!w62A35WWWXg
IkarusBackdoor.Win32.Banito
FortinetW32/Banito.CN!tr
BitDefenderThetaGen:NN.ZexaF.34062.qqX@a8HRoNnb
AVGWin32:Unruy-B [Trj]
Cybereasonmalicious.84a7d9
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove BScope.Worm.Chiviper?

BScope.Worm.Chiviper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment