Trojan

What is “Trojan.Chydo”?

Malware Removal

The Trojan.Chydo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Chydo virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Trojan.Chydo?


File Info:

name: 125345B4159DA1818172.mlw
path: /opt/CAPEv2/storage/binaries/b9b7d76c518808d280ee6f68318fce842219d0d608f64d443f28771d740b78e5
crc32: EAB805B7
md5: 125345b4159da1818172cdac5901941e
sha1: 513a7dbf2fc4440c14c2a2cb4750e5d70d0e8f07
sha256: b9b7d76c518808d280ee6f68318fce842219d0d608f64d443f28771d740b78e5
sha512: e3a8370aeba8b1f3dc03714fc54455674c459b85a4f32497686ff18bd6921534b8ea1d9c3b84e0eab3c7ad4658b644a775c971b91ef5d7beabb1331343942beb
ssdeep: 12288:o6bvdl0zCB8EDItMTzwg7lMQsvNuqZBRbZEYTwdD7IjLgXTx5KEZh:5vdezCByqTtlMQsFuqzRbzI7Iih
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0C4F11CFA958D3FDE1746FC905AC5EE5B5B9DA305D4002727F4BBCE9AB12A0800ED29
sha3_384: 8ce8caab21c47da4d60a3f98bcf221e331e02583c52f4080c2195c5c99632e6e1f3628db4b6902f9a039759005aa8189
ep_bytes: 6a606870714000e87f030000bf940000
timestamp: 2009-04-17 17:23:08

Version Info:

0: [No Data]

Trojan.Chydo also known as:

BkavW32.FamVT.MyurenDC.Trojan
LionicTrojan.Win32.Generic.lvMt
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop5.14836
MicroWorld-eScanTrojan.Dropper.VIO
FireEyeGeneric.mg.125345b4159da181
CAT-QuickHealTrojan.KillAv.DR
McAfeeBackDoor-EJG
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 003b31ad1 )
BitDefenderTrojan.Dropper.VIO
K7GWTrojan ( 003b31ad1 )
Cybereasonmalicious.4159da
ArcabitTrojan.Dropper.VIO
BitDefenderThetaAI:Packer.45FD971920
CyrenW32/KillAV.M.gen!Eldorado
SymantecW32.Pykspa!gen1
ESET-NOD32Win32/AutoRun.Agent.TV
TrendMicro-HouseCallWORM_MESSEN.SMF
Paloaltogeneric.ml
ClamAVWin.Malware.Pykspa-6723766-0
KasperskyWorm.Win32.AutoRun.iea
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Chydo.eahreo
ViRobotTrojan.Win32.Chydo.516096.B
RisingDownloader.Dwonk!1.662D (CLASSIC)
Ad-AwareTrojan.Dropper.VIO
EmsisoftTrojan.Dropper.VIO (B)
ComodoWorm.Win32.AutoRunAgent.TV2@1lq8ot
BaiduWin32.Worm.Autorun.j
ZillyaWorm.AutoRun.Win32.116380
TrendMicroWORM_MESSEN.SMF
McAfee-GW-EditionBehavesLike.Win32.Backdoor.hc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-R + Troj/Bckdr-RAK
IkarusTrojan-Dropper.Agent
JiangminTrojan/Chydo.bj
MaxSecureWorm.Agent.adx
AviraTR/AD.Kypes.aroap
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojanDropper:Win32/Pykspa.A
SUPERAntiSpywareTrojan.Agent/Gen-KillAV
GDataWin32.Trojan.PSE.1IFY41
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Chydo.R40147
Acronissuspicious
ALYacTrojan.Dropper.VIO
TACHYONTrojan/W32.Chydo.569344.E
VBA32BScope.Worm.Chydo
MalwarebytesTrojan.Chydo
PandaGeneric Malware
APEXMalicious
TencentTrojan.Win32.FakeAlert.ate
YandexWorm.Agent!fjpTjPncbb0
MAXmalware (ai score=82)
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.LGB!tr
AVGWin32:Chydo [Drp]
AvastWin32:Chydo [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Chydo?

Trojan.Chydo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment