Trojan

How to remove “Trojan-Banker.Win32.ChePro.nijg”?

Malware Removal

The Trojan-Banker.Win32.ChePro.nijg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ChePro.nijg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Starts servers listening on 0.0.0.0:5405
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Collects information about installed applications
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
s2s.takemyfile.net
st.priceyam.xyz
inlgfiles.com
rep.pe-wok.biz
workinghoursfive.xyz
geo.netsupportsoftware.com
workingplacesfive.xyz
onetaponebat.xyz
www.bing.com
ocsp.digicert.com
vict-load.com
www.findmemolite.com

How to determine Trojan-Banker.Win32.ChePro.nijg?


File Info:

crc32: 14238F6E
md5: c3cf2e1995002044bdc380e66909c34b
name: C3CF2E1995002044BDC380E66909C34B.mlw
sha1: 805a47727e2234d7c802e83e9550defea76ee0e8
sha256: 284ec50e68cea202ff266e2234c183d8d2748d0b5fd1f1729cca54c6d82634a2
sha512: 67aefbc72b277bf3048abb858dfc2e761050db7b8ef603c298746f7ab0f387c57a1e5111c0f1766ff6c979f2187ea75fd888bf3cebae96744d1bea58d8d1720a
ssdeep: 24576:t4nXubIQGyxbPV0db26WB7qKn3L7ujsv1Et9uGpckT52zedlq89Ws5uIzk5aM/pB:tqe3f6g52gSffPMWrQ0ZkJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Activator for Windows 7 v5.7.1
ProductVersion: 1.0
FileDescription: Activator for Windows 7 v5.7.1 Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.ChePro.nijg also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.ChePro.7!c
DrWebTrojan.PWS.Stealer.30446
CynetMalicious (score: 100)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanBanker:Win32/ChePro.1c950fab
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
AvastFileRepMalware
ClamAVWin.Dropper.NetSupportManager-9873726-1
KasperskyTrojan-Banker.Win32.ChePro.nijg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
AhnLab-V3Malware/Win.Generic.C4540454
McAfeeArtemis!C3CF2E199500
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ChePro.NIEP!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.ChePro.HgIASXwA

How to remove Trojan-Banker.Win32.ChePro.nijg?

Trojan-Banker.Win32.ChePro.nijg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment