Trojan

What is “Trojan-PSW.Win32.Chisburg”?

Malware Removal

The Trojan-PSW.Win32.Chisburg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Chisburg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Chisburg?


File Info:

crc32: BED6A7D8
md5: bfdc7ac0e240105924763da04f2e45fd
name: arinze.exe
sha1: b3b72e8c8fa8f888926e8b3d01ab448d178c557c
sha256: 446e55249a19fcefa746b41fc9ca16bf38c7e876b8334e46b92f53133269d78f
sha512: cbb8f050ba747ca8be11321cc09c80517193f1e4bae722599dc044bca78b5f3700bd29d3b22de9a1a7158e3d6c47a2a26be58ed4cc77c7b75581bb39f4ca186c
ssdeep: 24576:/Bcin4DWYW1aRamk8C2xzruPZp6AgV5PfA:/BjnISGLPxHuBp6AgvP4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Chisburg also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33555492
Qihoo-360Win32/Trojan.PSW.63c
McAfeeArtemis!BFDC7AC0E240
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33555492
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c8fa8f
TrendMicroTrojanSpy.Win32.LOKI.SMDF.hp
F-ProtW32/Trojan2.QBQU
SymantecRansom.Wannacry
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.33555492
KasperskyHEUR:Trojan-PSW.Win32.Chisburg.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
RisingTrojan.Injector!1.AFE3 (CLASSIC)
Ad-AwareTrojan.GenericKD.33555492
SophosMal/Fareit-V
DrWebTrojan.PWS.Siggen2.45058
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bfdc7ac0e2401059
EmsisoftTrojan.GenericKD.33555492 (B)
IkarusTrojan.Inject
CyrenW32/Trojan.JHLN-8204
JiangminTrojan.PSW.Chisburg.bgl
WebrootW32.Loki.Smdf
Antiy-AVLTrojan/Win32.Formbook
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2000424
ZoneAlarmHEUR:Trojan-PSW.Win32.Chisburg.gen
MicrosoftTrojan:Win32/FormBook.AQ!MTB
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34100.5GW@aaIJ3jii
ALYacTrojan.GenericKD.33555492
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.ELCU
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDF.hp
YandexTrojan.Injector!RN9OPdZIqj0
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELDL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Chisburg?

Trojan-PSW.Win32.Chisburg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment