Trojan

Trojan-Banker.Win32.ChePro.nitt removal

Malware Removal

The Trojan-Banker.Win32.ChePro.nitt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ChePro.nitt virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Trojan-Banker.Win32.ChePro.nitt?


File Info:

name: 66DB87EEC2FD9F7E0173.mlw
path: /opt/CAPEv2/storage/binaries/5669f6a48dac80717fa5770fa3be6c18022a7633b996ccf0df6b468994085378
crc32: 51C3E6A0
md5: 66db87eec2fd9f7e0173af421220f75e
sha1: 6de335e4267b613a212a1c2a6a37627de73a5199
sha256: 5669f6a48dac80717fa5770fa3be6c18022a7633b996ccf0df6b468994085378
sha512: 688bc8e46a4041259c1d9fdc8fd98d4feaabc1065384b829dbdbc3de332e1f22d9344161624665ae86288059f089b5b1440bdfff065855c337e95f3f01ff7c46
ssdeep: 49152:qyxWJ93/1E7WB85g6uwZn6pixPo77rwwdJoXImxuH3N4Un5uvkf9LV:qyUJ9/iaB8VuOn6wxPoDbdJoJxuOYAvs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17EC51223D2D3175BC86F1B7868AD53A459D1FC0FEF2685A50E80F60FA47C62409EA793
sha3_384: 0d1dae70806037f99ffe5026f09287896fe1c652722ad2e4cc55ea61a3eb0cf0a70361b5166d635f6b22adeb4cac2141
ep_bytes: e81effffff33c050505050e8ea2b0000
timestamp: 2011-03-02 07:40:33

Version Info:

0: [No Data]

Trojan-Banker.Win32.ChePro.nitt also known as:

LionicRiskware.Win32.NetSup.1!c
MicroWorld-eScanAdware.GenericKD.48331965
CAT-QuickHealPUP.RemoteAdmin
McAfeeArtemis!66DB87EEC2FD
CylanceUnsafe
SangforTrojan.Win32.ChePro.nitt
K7AntiVirusRiskware ( 00589e5c1 )
AlibabaTrojanBanker:Win32/ChePro.4093293e
K7GWRiskware ( 00589e5c1 )
VirITBackdoor.Win32.RMS.GR
CyrenW32/S-f514affe!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32Win32/RiskWare.RemoteAdmin.NetSupportManager.H
TrendMicro-HouseCallPUA.Win32.RemoteAdmin.AY
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.ChePro.nitt
BitDefenderAdware.GenericKD.48331965
APEXMalicious
Ad-AwareAdware.GenericKD.48331965
EmsisoftAdware.GenericKD.48331965 (B)
DrWebBackDoor.RMS.173
ZillyaTool.NetSup.Win32.66
TrendMicroPUA.Win32.RemoteAdmin.AY
McAfee-GW-EditionPUP-RemoteAdmin.a
FireEyeAdware.GenericKD.48331965
SophosGeneric PUA GN (PUA)
IkarusTrojan.Win32.RA
GDataWin32.Riskware.NetRemote.A
JiangminRemoteAdmin.NetSup.ai
WebrootW32.Malware.Gen
MAXmalware (ai score=63)
ArcabitAdware.Generic.D2E17CBD
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ALYacAdware.GenericKD.48331965
VBA32Trojan.Tiggre
TencentWin32.Trojan-banker.Chepro.Wqxf
YandexRiskware.RemoteAdmin!qOXgk+8XT2U
MaxSecureTrojan.Malware.140186501.susgen
FortinetRiskware/PUP_RemoteAdmin
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.Win32.ChePro.nitt?

Trojan-Banker.Win32.ChePro.nitt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment