Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2021

How to remove CHIP ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

CHIP virus authors use RIG exploit kit for distribution

Image of CHIP ransomware virus

CHIP virus is a ransomware-type infection[1] created for the sole purpose of extorting money from the infected computer owners. In most cases, cybercriminals use exploit kits such as RIG to propagate the virus, although some cases of brute-force attacks were also observed.

Once installed, malware appends each of the personal files with .CHIP or .DALE extensions thanks to the encryption process, which is performed with a strong RSA[2] encryption algorithm. Soon after, victims can see a ransom note, titled “CHIP_FILES.txt” or “DALE_FILES.txt,” which explains to victims what happened with their data and that they need to visit a specific .onion website and contact criminals through it for further details. As evident, malicious actors would ask a ransom to be paid in Bitcoin cryptocurrency, although agreeing with these demands might cost you your money.

Name CHIP ransomware
Type File-locking virus, crypto-malware
Extension .CHIP or .DALE
Cipher RSA
Contact Users can be asked to visit a unique .onion web address via the TOR browser or contact hackers directly via  grion@protonmail.com or similar email
Malware elimination Use SpyHunterCombo Cleaner or another reputable anti-malware to delete all malware on your system
System fix Malware can seriously damage Windows system files, which may later result in crashes or errors. To remediate this damage automatically, we recommend using FortectIntego

The files encrypted by this ransomware can be uncovered by finding a particular extension added to them. Usually, these viruses are programmed to target high-importance “working” content, including media files, Office documents, or PDF files.

It can also encrypt virtual or the most popular cloud drives,[3], so if you are thinking about backing up your data on such platforms to prevent ransomware attacks, you should start thinking about some other option. However, if infected, you need to remove the virus first because each second counts, and you can lose even more files stored on your computer.  

When the files are encrypted, the criminals drop the ransom note that manipulates their victims into paying considerable sums of money in order to regain the lost access to their personal data. According to the latest findings, they ask people to contact them via one of the following emails:

  • grion@protonmail.com
  • grion@techie.com
  • grion@dr.com
  • grion@protonmail.com, etc.

In some other malware versions, users might be asked to download the TOR browser and visit a particular page. There, victim ID and a comment should be added in order to begin communication with hackers.

We should remind you that this malware is a creation of cybercriminals who should not be trusted![4] These individuals may try to convince you into thinking that they are the only ones who can help you to get your data back, but please, keep in mind that security experts have already found alternative ways to help people recover their data.

By paying up, you only support the criminals, but by carrying out CHIP ransomware removal, you can diminish their motivation to move forward with the virus invention. We suggest doing just that and contributing to the battle against cyber infections.

Originally, the virus earned its name from the extensions it adds to the infected files. However, the latest its version uses .Dale file extension. Documents that feature such extensions are inaccessible and remain like this until they are decrypted using the offered decryption key, or in case the encryption is bypassed some other way. The targeted files are compromised by changing their inner structure.

For instance, after the encryption, information on a Word document will be replaced by a jumble of unintelligible symbols. The number of symbols indicates the complexity of encryption: the more symbols – the stronger encryption. To solve this problem, the hackers offer the victim to purchase a private decryption key which will supposedly bring these files in their previous order.

On the infected computer, the virus automatically drops a ransom note in which this data retrieval process is explained in more detail, as can be seen in an example below:

YOUR ID:[random_string_of_characters]
Hello! All Your files are encrypted! For more specific instructions,
please visit a support home page: hxxp://mm6x57ri2coivya6.onion
To see this page follow these steps: 1 – Download and install tor-browser: hxxp://www.torproject.org/projects/torbrowser.html.en
2 – After a successful installation, run the browser
3 – Type in the address bar – hxxp://mm6x57ri2coivya6.onion
4 – Follow the instructions on the site
Attention: DO NOT USE ANY PUBLIC DECRYPTERS! YOU CAN DAMAGE YOUR FILES!
Kind regards,
Support Team.
YOUR ID:[random_string_of_characters]

As you can see, the hackers are not willing to discuss the financial issues immediately and urge the victims to access the predetermined payment site first. Even after that, the victims are asked to provide their own email address so that the hackers could contact them privately. The notice is declared as follows:

Hello!
Your files are encrypted!
If You want to restore Your system, You need to use a contact form below.
Leave Your ID number (ID number is located in the “CHIP_FILES.TXT”) and contact email.
Our appointment coordinators will contact you within 24 hours!
Attention: DO NOT USE ANY PUBLIC DECRYPTERS! YOU CAN DAMAGE YOUR FILES!

It is likely that after you contact the criminals, you will be asked to transfer them a ransom that ranges from $500 to $1,000. Even with such large sums at play, you are never guaranteed that your files are safe and will be decrypted. Thus, the most rational decision in such a case is to remove the virus, try to recover the encrypted data via alternative techniques and take steps to protect your future data, namely, create backup copies of your files.

Malware distribution methods

When it comes to distributing this ransomware strain, we have to say that it is pretty basic. The virus primarily attacks computers through spam emails. Hackers have become surprisingly good at creating persuasive emails that inform about a tax refund, delivery confirmation, flight bookings, and similar issues, which, in reality, work as a hook to get the targeted victims to download malicious files.[5]

Thus, you should never rush to open similar emails or download attached files, even if the sender is an authoritative company or institution. If you are not cautious enough and download one of the infected .js, .wsf, .hta, .html files that virus developers use to distribute this virus, you may get infected and lose your files. Stay vigilant and stay away from such emails as far as possible at the same time taking care of your data backups.

Get rid of the virus and only then attempt file recovery

Without a doubt, ransomware is by far the most damaging type of malware that one can get infected with. The unique key that is used during the encryption is what stops people from an easy recovery after the infection. However, keep in mind that you can mitigate most of the damage caused by simply preparing regular data backups.

If you have none ready, you need to first copy the locked files over to a separate medium, for example, a USB drive. Then, you can remove malware from your system by scanning your PC with SpyHunterCombo Cleaner or another antivirus software. Don't forget to repair damaged system components – you might have to reinstall Windows for that. Alternatively, you can employ FortectIntego.

Finally, look for alternative data recovery solutions we provide below. Keep in mind that using them might not necessarily result in a positive outcome for you, although paying criminals is by far a worse choice to make. 

 

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.