Trojan

Should I remove “Trojan.Win32.Chapak.anoe”?

Malware Removal

The Trojan.Win32.Chapak.anoe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.anoe virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Czech
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Trojan.Win32.Chapak.anoe?


File Info:

crc32: 3968F4E0
md5: 29d982bd15512b64f0e2a63575ac0c25
name: 29D982BD15512B64F0E2A63575AC0C25.mlw
sha1: b0efd22b411e5c93f160421c027123e5f91b83a2
sha256: 432d2e975795958ae080fa74c945ee7c401145cde3caa9c8775da1b6c1da1ce6
sha512: 75c6d33cf0ad1951e0f4fd433e73bb899404377e214c0ec43015b7d259566e9496a85e0459c06a00f00a144a85c0cd292fc22b5c0fae00c30a1423567c13be67
ssdeep: 3072:p6Pzl1FQC2mCe0pXM1wigJ7gT5hvQk+pUkMKxlsKksBA6NyXP96w8R/:p6PzYxM1jg1gTL41MilNkswf96w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe
FileVersion: 8.4.3.12

Trojan.Win32.Chapak.anoe also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.GandCrab.1903
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.9276
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Chapak.08e8655c
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.d15512
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJRD
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Chapak.anoe
BitDefenderGen:Variant.Ransom.GandCrab.1903
NANO-AntivirusTrojan.Win32.Chapak.fifekw
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1903
TencentWin32.Trojan.Chapak.Hugf
Ad-AwareGen:Variant.Ransom.GandCrab.1903
SophosMal/Generic-S + Mal/GandCrab-G
BitDefenderThetaGen:NN.ZexaF.34758.nu0@aSrQKMiG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.29d982bd15512b64
EmsisoftGen:Variant.Ransom.GandCrab.1903 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.nz
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1103322
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.277BA2A
MicrosoftRansom:Win32/GandCrab.AT!bit
AegisLabTrojan.Win32.Chapak.4!c
GDataGen:Variant.Ransom.GandCrab.1903
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeePacked-FKN!29D982BD1551
MAXmalware (ai score=99)
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!DJKV6anhAB4
IkarusTrojan-Downloader.Win32.Zurgop
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GKJF!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Win32.Chapak.anoe?

Trojan.Win32.Chapak.anoe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment