Ransom

About “Ransom:Win32/Chaicha” infection

Malware Removal

The Ransom:Win32/Chaicha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Chaicha virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings

How to determine Ransom:Win32/Chaicha?


File Info:

crc32: 139BDE19
md5: fdbc8562ec9dd7bdc709326e53063a88
name: FDBC8562EC9DD7BDC709326E53063A88.mlw
sha1: 21f2fed534acade36949dcfd24c43d8d651fcbeb
sha256: 90f833dea9e0edc542eb2b9af443ee2fc1377e8c7102f6777ef8ea7d01c69c31
sha512: 95e948207a83a7b243537dc2eb1a20d9f01102bac3d8c35e4e54dd882bbe9df7078b8487626efed6b0fd247ad42aa51812211a8a0b2e0f42d1f3645889ac4d6a
ssdeep: 768:tzCL/eaYVTGDqH49MarIPtTX7PZsQ2UYVWUI48JL6AxI:ELmaYV7Y9DrIJPaQ2Uw1OL6oI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Chaicha also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053c24c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26314
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Chaicha.8b7edd9e
K7GWTrojan ( 0053c24c1 )
Cybereasonmalicious.2ec9dd
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.STOP.A
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Scar.rmry
BitDefenderTrojan.Ransom.Stop.A
NANO-AntivirusTrojan.Win32.GenKryptik.fhjvrh
ViRobotTrojan.Win32.S.Ransom.73728.A
MicroWorld-eScanTrojan.Ransom.Stop.A
TencentWin32.Trojan.Scar.Ehia
Ad-AwareTrojan.Ransom.Stop.A
SophosMal/Generic-R + Troj/SaveFile-A
ComodoMalware@#1olp2lrjw31xq
BitDefenderThetaGen:NN.ZexaF.34678.emW@auY1xlo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.lm
FireEyeGeneric.mg.fdbc8562ec9dd7bd
EmsisoftTrojan.Ransom.Stop.A (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Scar.mpv
AviraHEUR/AGEN.1128881
MicrosoftRansom:Win32/Chaicha
ArcabitTrojan.Ransom.Stop.A
AegisLabTrojan.Win32.Scar.4!c
GDataTrojan.Ransom.Stop.A
AhnLab-V3Trojan/Win32.Savefiles.C2701916
Acronissuspicious
McAfeeGenericRXGL-AQ!FDBC8562EC9D
MAXmalware (ai score=99)
VBA32BScope.Trojan.Fuerboos
MalwarebytesRansom.Chaicha
PandaTrj/GdSda.A
RisingRansom.Chaicha!1.B411 (CLOUD)
YandexTrojan.GenAsa!63E9njbx5x8
IkarusTrojan.Win32.Krypt
FortinetW32/Filecoder.GA!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Chaicha?

Ransom:Win32/Chaicha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment