Trojan

About “Trojan.ChinAd” infection

Malware Removal

The Trojan.ChinAd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ChinAd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

fget-career.com
bing.com
yahoo.com
www.qq5.com

How to determine Trojan.ChinAd?


File Info:

crc32: 8AAC6FD5
md5: 5fa9cefc2fe76ae139f3f24b67f27967
name: majiangpinpan.exe
sha1: f2116803a0826ec1538f177cd3bf002a5925dee5
sha256: 55910940427d57a740f2d4808aa7541ed67411ad7ee84d687bcc48a3ff2432f7
sha512: f4ae2bcb2e45f557ad3bf46be73e885f89d42251c5bceef5c31c4b29af0d0e677ce24a6457cef9e88f1bff4719535268ef79d51d1ae039cbdfb1a185aba000d8
ssdeep: 196608:OoOqUVFkdHPdKFdI1SiZDuwrKIN/eLz3557gVwlXc3R:OoODVIvdK8tF/eekz3X7hlMh
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

Trojan.ChinAd also known as:

DrWebAdware.Searcher.1222
MicroWorld-eScanDropped:Trojan.Zbot.IVF
FireEyeDropped:Trojan.Zbot.IVF
CAT-QuickHealW32.Ramnit.A
Qihoo-360Win32/Virus.IM.0e1
CylanceUnsafe
ZillyaDropper.Agent.Win32.409511
K7AntiVirusTrojan ( 0050b64b1 )
BitDefenderDropped:Trojan.Zbot.IVF
K7GWTrojan ( 0050b64b1 )
Cybereasonmalicious.c2fe76
TrendMicroPE_RAMNIT.H
BitDefenderThetaAI:FileInfector.EAEEA7850C
F-ProtW32/Ramnit.B!Generic
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ramnit-1847
GDataDropped:Trojan.Zbot.IVF
KasperskyVirus.Win32.Nimnul.a
AlibabaVirus:Win32/Nimnul.927048a8
NANO-AntivirusVirus.Win32.Ramnit.eslalb
AegisLabVirus.Win32.Nimnul.n!c
RisingVirus.Ramnit!1.9AA5 (CLASSIC:bWQ1Or0F/riCWxXc3ZEA1HjwThc)
Ad-AwareDropped:Trojan.Zbot.IVF
EmsisoftAdware.Dropper (A)
ComodoMalware@#3qz6vol2ebvso
F-SecureMalware.W32/Ramnit.CD
BaiduMulti.Threats.InArchive
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Virus.vc
Trapminemalicious.moderate.ml.score
SophosW32/Patched-I
IkarusVirus.Ramnit
CyrenW32/Ramnit.B!Generic
JiangminWin32/PatchFile.et
WebrootW32.Malware.Heur
AviraW32/Ramnit.CD
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
ArcabitTrojan.Zbot.IVF
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.A
VBA32Virus.Win32.Nimnul.a
ALYacDropped:Trojan.Zbot.IVF
MalwarebytesTrojan.ChinAd
PandaGeneric Suspicious
ZonerTrojan.Win32.Ramnit.23698
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TrendMicro-HouseCallPE_RAMNIT.H
TencentWin32.Virus.Nimnul.Tafp
AVGWin32:RmnDrp
AvastWin32:RmnDrp
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureVirus.Nimnul.A

How to remove Trojan.ChinAd?

Trojan.ChinAd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment