Worm

Worm:Win32/Cheval.D removal instruction

Malware Removal

The Worm:Win32/Cheval.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Cheval.D virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Cheval.D?


File Info:

name: 144CDC05AE1BF09D7916.mlw
path: /opt/CAPEv2/storage/binaries/75c315b346a011dd52d4ce8d2245d8f203ca42c9279a5c32dafe3d88a3f9dc7a
crc32: 0947AAFD
md5: 144cdc05ae1bf09d7916f7a66e949611
sha1: 1d274e263c8aa0763a40c0e4f73a844ec5505a78
sha256: 75c315b346a011dd52d4ce8d2245d8f203ca42c9279a5c32dafe3d88a3f9dc7a
sha512: e08e5021120ffaf956b19960811d50fac28ad9fd6e504cfd49172e5138a7be1f5d24d46ffc1e3aada4fa709e89ea3f5ac093009065ea98a1cf191c0a67c21e3e
ssdeep: 12288:65h3PhAT+T3Y5Z7djjyoGt87O7aXp5eoV6:63PGa3Y5v36jaXp5N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187F44C26F690C833D1321E389D4B87949C26BE503E38DD4B3BF95E4C5E7978179262A3
sha3_384: 6bfe4b08b85f9259cfa9b87c18c9e753e9e3567cf39d7e25b5bf6201db8bf9d9d6ef1fc597d72be1a811a92f0f51d790
ep_bytes: 558bec83c4f4b8fc994500e8a8bdfaff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: http://www.bome.com
FileDescription: Icon changer package
FileVersion: 1.0
InternalName: IconChange
LegalCopyright: © 1998 by Florian Bömers
OriginalFilename: IconChange.dpk
ProductVersion: 1.0
Translation: 0x0409 0x04e4

Worm:Win32/Cheval.D also known as:

LionicTrojan.Win32.Snojan.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.65945398
ClamAVWin.Trojan.DeTroie-1
ALYacTrojan.GenericKD.65945398
MalwarebytesDetroie.Virus.FileInfector.DDS
VIPRETrojan.GenericKD.65945398
SangforTrojan.Win32.Save.ShadowBrokersC
K7AntiVirusTrojan ( 0052964f1 )
AlibabaWorm:Win32/Cheval.1988
K7GWTrojan ( 005662a41 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Banbra.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/HLLP.DeTroie
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Snojan.gen
BitDefenderTrojan.GenericKD.65945398
NANO-AntivirusVirus.Win32.DeTroie.bbxbrd
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Cheval
TencentVirus.Win32.Hllp.aad
EmsisoftTrojan.GenericKD.65945398 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebWin32.HLLP.Cheval
ZillyaTrojan.Banbra.Win32.29438
TrendMicroTROJ_GEN.R002C0DEL23
McAfee-GW-EditionBehavesLike.Win32.Trojan.bt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.144cdc05ae1bf09d
SophosW32/Cheval-C
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.65945398
JiangminTrojan.Banker.Banbra.ben
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumVirus.Win32.HLLP.DeTroie.E@n97ec
ArcabitTrojan.Generic.D3EE3F36
ZoneAlarmHEUR:Trojan.Win32.Snojan.gen
MicrosoftWorm:Win32/Cheval.D
GoogleDetected
AhnLab-V3Trojan/Win32.Banbra.R259320
Acronissuspicious
McAfeeGenericRXAA-AA!144CDC05AE1B
MAXmalware (ai score=82)
VBA32Trojan.Snojan
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEL23
RisingWorm.Cheval!1.A14A (CLASSIC)
IkarusVirus.Win32.HLLP.DeTroie
MaxSecureTrojan.Malware.11743943.susgen
FortinetW32/HLLP.DeTroie.A
BitDefenderThetaGen:NN.ZelphiF.36196.Wq3@ame3FBbe
AVGWin32:Cheval
Cybereasonmalicious.5ae1bf
DeepInstinctMALICIOUS

How to remove Worm:Win32/Cheval.D?

Worm:Win32/Cheval.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment