Malware

Win32/Injector.CHAB removal

Malware Removal

The Win32/Injector.CHAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CHAB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.CHAB?


File Info:

name: ABF802B665F65D3D7D3D.mlw
path: /opt/CAPEv2/storage/binaries/8e99cf8022867e7e6e0456b4f8d16700db4e6ea3034010c6c03ba1e783ead3bb
crc32: B37B70F5
md5: abf802b665f65d3d7d3d8efd7dfe2cae
sha1: 2bc2c2ef2e34cf1d99f116f151bf1457c14665fb
sha256: 8e99cf8022867e7e6e0456b4f8d16700db4e6ea3034010c6c03ba1e783ead3bb
sha512: 8093b1d303d0a6148e97bec9a659d04a5b3bd227bc50e3ab6442f741efe11ea0c9c50a3cc953c6350aad6bb790f4f5ddc7d3d29172bd1dc82ccae637c05e2734
ssdeep: 1536:whFh0hhDf4LH44bG1U2EhWhguN7fJrd+iji2gk945PY2HFxGV:37DfEi1U2aEnN73+iji2pe9hHFxGV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103A39D05535D0292F7A765308D2179734AB5AC7C325F9B6FF385CE5E60A9EC04880BAF
sha3_384: 9763994ec407c0483b62e49be0442e6fb6c94bd933bb094dd4784a7175b0e3ab080e2195791448e3a440e7874cdb6a44
ep_bytes: 558bec6aff688074400068e26c400064
timestamp: 2015-08-05 12:17:08

Version Info:

0: [No Data]

Win32/Injector.CHAB also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
tehtrisGeneric.Malware
DrWebBackDoor.Siggen.59488
MicroWorld-eScanGen:Variant.Ransom.Seven.17
FireEyeGeneric.mg.abf802b665f65d3d
CAT-QuickHealTrojan.Ceeinject.17924
SkyhighPWSZbot-FAKV!ABF802B665F6
McAfeePWSZbot-FAKV!ABF802B665F6
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ransom.Seven.17
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005556b41 )
AlibabaTrojan:Win32/Bulta.9e98fc73
K7GWTrojan ( 005556b41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.gy3@aCuTtWdb
VirITTrojan.Win32.SHeur4.CLBA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.CHAB
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
ClamAVWin.Malware.Generickdz-7001603-0
KasperskyTrojan.Win32.Agent.igdw
BitDefenderGen:Variant.Ransom.Seven.17
NANO-AntivirusTrojan.Win32.BotFAKV.fvlgbw
TencentTrojan.Win32.Inject.vgce
EmsisoftGen:Variant.Ransom.Seven.17 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Agent.Win32.3877199
TrendMicroBKDR_KELIHOS.SMB
Trapminemalicious.moderate.ml.score
SophosMal/Zbot-UE
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Hlux.gmk
VaristW32/S-d76abcba!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Amadey.RPY!MTB
XcitiumTrojWare.Win32.Spy.Zbot.SBB@5te8th
ArcabitTrojan.Ransom.Seven.17
ZoneAlarmTrojan.Win32.Agent.igdw
GDataGen:Variant.Ransom.Seven.17
GoogleDetected
AhnLab-V3Trojan/Win32.MDA.R162581
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Ransom.Seven.17
TACHYONBackdoor/W32.Hlux.98554.B
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SMB
RisingTrojan.DllCheck!8.117DB (TFE:1:k8iicbVp6TV)
YandexTrojan.GenAsa!3Dk3U47badU
IkarusTrojan.Win32.Kelihos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CHLV!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Seven

How to remove Win32/Injector.CHAB?

Win32/Injector.CHAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment