Worm

Worm:Win32/Chupik.A removal guide

Malware Removal

The Worm:Win32/Chupik.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Chupik.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs a browser addon or extension
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Worm:Win32/Chupik.A?


File Info:

crc32: FC7FC860
md5: 739057fcd75e136e9c8c6ffb64a7da80
name: 739057FCD75E136E9C8C6FFB64A7DA80.mlw
sha1: 2a7a26b594eb1fcf15d8a18580a6d5023b80473b
sha256: 05aca61cff939f6fbbd36f6ef9e99214be914f055e7c7a9f6ace09e05e3085f8
sha512: de7cdd458eefadbcc47fce46ef88ed61e7c2b87d40209dacd4bf5e37dad17ffd1c3eaa1afee1aaaa30e35535e394e6a5686081e75075a031ba9f632dcd1ccdbb
ssdeep: 1536:6jPzy7rAVb3n3gX72IEJ5NwE4G/a3hd+g/:wPzyXANQX729D4G/aR3
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: pikachu
FileVersion: 1.00
OriginalFilename: pikachu.exe
ProductName: Project1

Worm:Win32/Chupik.A also known as:

BkavW32.PikachuGTA.Worm
TotalDefenseWin32/Chupika.A
MicroWorld-eScanWorm.Generic.270622
nProtectWorm/W32.Agent_Packed.195072
CAT-QuickHealWorm.Chupik
ALYacWorm.Generic.270622
MalwarebytesTrojan.Agent
ZillyaWorm.VB.Win32.2095
CrowdStrikemalicious_confidence_100% (W)
K7GWP2PWorm ( 000a677e1 )
K7AntiVirusP2PWorm ( 000a677e1 )
ArcabitWorm.Generic.D4211E
TrendMicroWORM_VB.SMLF
BaiduWin32.Trojan.Agent.at
CyrenW32/Worm.LPKA-4508
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.NSP
ZonerI-Worm.VB.NSP
TheHackerW32/VB.aso
AvastWin32:Downloader-VCO [Trj]
ClamAVLegacy.Trojan.Agent-1388589
KasperskyTrojan.Win32.Cosmu.dhrn
BitDefenderWorm.Generic.270622
NANO-AntivirusTrojan.Win32.Drop.crsvig
ViRobotWorm.Win32.VB.110592.B[h]
SUPERAntiSpywareTrojan.Agent/Gen-Pikachu
TencentWin32.Trojan.Agent.Mgen
Endgamemalicious (moderate confidence)
SophosMal/VB-F
ComodoWorm.Win32.Autorun.eb0
F-SecureWorm.Generic.270622
DrWebTrojan.MulDrop2.63234
VIPRETrojan.Win32.Generic!BT
Invinceaworm.win32.chupik.a
McAfee-GW-EditionBehavesLike.Win32.Autorun.cz
EmsisoftWorm.Generic.270622 (B)
SentinelOnestatic engine – malicious
F-ProtW32/Worm.APUJ
JiangminWorm/VB.auk
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLWorm/Win32.VB
KingsoftWin32.Virut.ce.57344
MicrosoftWorm:Win32/Chupik.A
Ad-AwareWorm.Generic.270622
AegisLabW32.W.VB.lmun
ZoneAlarmTrojan.Win32.Cosmu.dhrn
GDataWorm.Generic.270622
AhnLab-V3HEUR/Fakon.mwf
McAfeeW32/Worm-FEL!739057FCD75E
AVwareTrojan.Win32.Generic!BT
VBA32Worm.VB
PandaW32/Picachu.A.worm
TrendMicro-HouseCallWORM_VB.SMLF
RisingTrojan.Generic (cloud:9lgJO2b3QXV)
YandexTrojan.ATRAPS!o3gl8DrWSl8
IkarusWorm.Win32.VB
FortinetW32/VB.SDE!tr
AVGWorm/VB.BFJZ
Paloaltogeneric.ml
Qihoo-360HEUR/QVM11.1.Malware.Gen

How to remove Worm:Win32/Chupik.A?

Worm:Win32/Chupik.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment