$ 11.99|https://store.pandasecurity.com/300/purl-vpn?currencies=USS&x-track=55499&cart=iA001PVPNS05&language=en&quantity=1&enablecoupon=false&coupon=1STMOFFPD&x-coupon=1STMOFFPD&x-market=usa&x-track=190478|$ 0.00|$;PREFIX;.;,;11;99;0;00

It ends in:

Days Hours Minutes

It ends in:

Days Hours Minutes

The best protection with a 60% discount

Apply discount

Get 40% discount! Discover the plan that suits you best!

See offer

Get 40% discount! Discover the plan that suits you best!

See offer

Renew and get 50% off*

Only available for 48 hours!

::

*For home users only

Renew at a discount
::

Renew and get 50% off*

Renew
*Home users only

*For home users only Renew and get 50% off*

::
Renew

Special offer: Renew and get 50% off**

Only available for 48 hours!

::

*For home users only

Renew at a discount

*For home users only Special offer: Renew and get 50% off*

::04
Renew

Hello!

You’re about to visit our web page in English
Would you like to continue?

Yes, I want to visit the web page in English No, I want to visit the web page in

If this is not what you’re looking for,

Visit our Welcome Page!

Call us 24/7 and get a free diagnosis 951 203 528

Active Scan. Scan your PC free

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Chir.B

 
Threat LevelModerate threatDamageHighDistributionNot widespread

Effects 

Chir.B activates when the attachment is run. From that moment, the worm has the following effects:

  • It infects files with the following extensions: EXE, SCR, HTM and HTML.
  • On the first day of each month, it overwrites the first 4,660 bytes of files with the following extensions: ADC, R.DB, DOC and XLS.

Infection strategy 

Chir.B creates the following files:

  • RUNOUCE.EXE, in the Windows system directory. This file is a copy of the worm.
  • README.EML, in the directories in which the worm finds and infects files with an HTM and/or HTML extension. This file contains the worm's code in MIME format.

Chir.B creates the following entry in the Windows Registry:

  • HKEY_LOCAL_MACHINE\ Software\ Microsoft\ Windows\ CurrentVersion\ Run
    Runonce = %sysdir%\ runouce.exe

    where %sysdir% is the system directory.
    By creating this entry, Chir.B ensures that it is run whenever Windows is started.

Means of transmission 

Chir.B spreads itself via e-mail. It follows the routine below:

  • It reaches the computer in an e-mail message with the following characteristics:

    Sender: one of the following:
    %sender's name%@yahoo.com
    Imissyou@btamail.net.cn


    Subject:
    %sender's name% is coming!

    Message: it does not contain any text.

    Attachments:
    PP.EXE
  • It activates when the attachment is run.
  • It sends itself out to the e-mail addresses it gets from the infected user's Address Book.

ARE YOU FACING ANY PC OR INTERNET RELATED PROBLEMS?
FREE SUPPORT INCLUDED. CALL US 24/7

powered by Anytech365