Trojan

About “Trojan-Banker.Win32.ChePro.nikf” infection

Malware Removal

The Trojan-Banker.Win32.ChePro.nikf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ChePro.nikf virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.ChePro.nikf?


File Info:

crc32: 9814FEF1
md5: 34404cbd63be9620885368460b387695
name: 34404CBD63BE9620885368460B387695.mlw
sha1: 60c64006ee78c63eea23037213c1edaacfa59e88
sha256: 41e82e314fceb906d8618dbaa5d622cdea1b453ed74e3d358b5aafee0030490a
sha512: d659688427cede51674ef89972812054affa0689332eeadca1bf9af65babc7d2f1c2975af68eb6a50ea6da84547df6861f2105ac1cdcae53fd0685c844d22a2d
ssdeep: 49152:KDESR4ctGua0qM8xTsP7VQNfnVLmLELJ6AXXe2dAayKlKvq/gZcE9hSzISQq+tte:tSj4umMaQjUCLAXjdrgphScSH+t7dq
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Pronomeca Senigi Company
FileVersion: Samideano Mia Corporation
CompanyName: Pronomeca Senigi Company
Comments: This installation was built with Actual Installer: http://www.actualinstaller.com
ProductName: NepTV Ofhjivj O Samo De
ProductVersion: Samideano Mia Corporation
FileDescription: NepTV Ofhjivj O Samo De Installation
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.ChePro.nikf also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebBackDoor.RMS.173
ALYacMisc.Riskware.netsupport
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.87656
SangforTrojan.Win32.ChePro.nikf
AlibabaTrojanBanker:Win32/ChePro.97e2af77
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.XEPU-8060
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.ChePro.nikf
BitDefenderTrojan.GenericKD.46611146
MicroWorld-eScanTrojan.GenericKD.46611146
Ad-AwareTrojan.GenericKD.46611146
TrendMicroTROJ_GEN.R06BC0PGD21
FireEyeGeneric.mg.34404cbd63be9620
EmsisoftTrojan.GenericKD.46611146 (B)
JiangminTrojan.Chapak.lpg
WebrootW32.Trojan.Gen
AviraTR/Spy.ChePro.kabqs
Antiy-AVLTrojan/Generic.ASMalwS.30FCC75
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2C73ACA
GDataTrojan.GenericKD.46611146
AhnLab-V3Malware/Win32.Generic.C4264343
McAfeeArtemis!34404CBD63BE
MAXmalware (ai score=83)
VBA32Trojan.Chapak
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H06GA21
YandexRiskware.RemoteAdmin!qOXgk+8XT2U
FortinetRiskware/ChePro
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.ChePro.HgIASYMA

How to remove Trojan-Banker.Win32.ChePro.nikf?

Trojan-Banker.Win32.ChePro.nikf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment