Malware

PWS:Win32/Chyup.B malicious file

Malware Removal

The PWS:Win32/Chyup.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Chyup.B virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PWS:Win32/Chyup.B?


File Info:

name: 03BDED78E61974F93382.mlw
path: /opt/CAPEv2/storage/binaries/054293d59d62c538b4038d9a4a3d349c73e19286f6856bc10b7446403974227a
crc32: 381ADD3E
md5: 03bded78e61974f9338273cbbadcf08e
sha1: 28c4bedc5979568a0af8f45322cd0880efac5c57
sha256: 054293d59d62c538b4038d9a4a3d349c73e19286f6856bc10b7446403974227a
sha512: f369913b50bcd418d043ad0e7542da1829df0c77918f46c9f5f6ad2dd991822d4b69acf6b43492b51eaef3b5b19dfba87fc90ded9d95eff160796fdbec76ff69
ssdeep: 768:/QD1FqQQqjfdGdCJlcEOueuosD5ewJ19DW31zYRik/hr/ZKQp4d2L/Pn:21FqQQWkEmwe6rDWtEX/hr/ZKq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14B034C92B9C3DC76D1729F7F8E02C66DED7A2E203D6428D3B2E92ECD9825242151D353
sha3_384: ce98c6330340493442d89278a19ee7d1795722935e2a135b6f1acdd9c144327b169591f47594a2a7fa79265ad63ba8e4
ep_bytes: 558bec83c4c4b8d4861413e848bcffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

PWS:Win32/Chyup.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.lfX8
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanGen:Variant.Fragtor.333536
FireEyeGeneric.mg.03bded78e61974f9
SkyhighBehavesLike.Win32.Worm.nh
McAfeeArtemis!03BDED78E619
MalwarebytesMalware.AI.4094378585
VIPREGen:Variant.Fragtor.333536
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0010a1741 )
AlibabaTrojanDownloader:Win32/Genome.54141a5b
K7GWTrojan ( 0010a1741 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.QGL
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Evo-gen [Trj]
KasperskyTrojan-Downloader.Win32.Genome.usl
BitDefenderGen:Variant.Fragtor.333536
NANO-AntivirusTrojan.Win32.TrjGen.bolsl
TencentWin32.Trojan-Downloader.Genome.Pzfl
EmsisoftGen:Variant.Fragtor.333536 (B)
F-SecureBackdoor.BDS/Delf.qzn
DrWebTrojan.DownLoad1.12285
ZillyaTrojan.Agent.Win32.79403
TrendMicroTROJ_CHYUP.SMX
Trapminemalicious.high.ml.score
SophosMal/Generic-S
Paloaltogeneric.ml
JiangminTrojanDownloader.Genome.cly
WebrootW32.Infostealer.Gen
VaristW32/Downloader.VFMJ-8567
AviraBDS/Delf.qzn
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Genome
KingsoftWin32.Troj.Unknown.a
MicrosoftPWS:Win32/Chyup.B
XcitiumMalware@#1x1vph8th7pgu
ArcabitTrojan.Fragtor.D516E0
ZoneAlarmTrojan-Downloader.Win32.Genome.usl
GDataGen:Variant.Fragtor.333536
GoogleDetected
BitDefenderThetaAI:Packer.BAB4E9C618
ALYacGen:Variant.Fragtor.333536
TACHYONTrojan-Downloader/W32.DP-Genome.38400
VBA32TrojanDownloader.Genome
Cylanceunsafe
PandaTrj/Hmir.F
TrendMicro-HouseCallTROJ_CHYUP.SMX
RisingBackdoor.Win32.Mnless.djk (CLASSIC)
YandexTrojan.GenAsa!YHlSjNYCmoI
IkarusTrojan-Downloader.Win32.Delf
MaxSecureTrojan.Malware.4843257.susgen
FortinetW32/Genome.USL!tr.dldr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Genome.usl

How to remove PWS:Win32/Chyup.B?

PWS:Win32/Chyup.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment