Trojan

Trojan.Win32.Chapak.edfz (file analysis)

Malware Removal

The Trojan.Win32.Chapak.edfz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.edfz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

live.windowchannel.bid
gool.eventhammer.bid

How to determine Trojan.Win32.Chapak.edfz?


File Info:

crc32: 32AE3878
md5: 8de99ed2b74ca114c1ff12817c6b6511
name: 8DE99ED2B74CA114C1FF12817C6B6511.mlw
sha1: 943621364d56948757a31f0287d0ac246d0791d6
sha256: 1fce06a13dbe6f05c92a067bae8d2f18ff8390883e2720ad45a2e765e33d16e2
sha512: 87486d39b46237bccaca5a4e6889623404e256c21b4a5746afc22d1188550b931e6880e7b2b6c794590338127dc25527d0188074777d86099fff69f2e815e4aa
ssdeep: 24576:4XyNwYccP5GYx01Wx3V5HdQnl+356kg8ej2vOj52nif1sxC:XNwYccP5GYx01Wx3V59QE3Dg8A2u4cs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Chapak.edfz also known as:

K7AntiVirusTrojan ( 00528e801 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.VittaliaENT.1
CAT-QuickHealSoftwareBundler.Prepscram.B7
ALYacApplication.Bundler.iStartSurf.DU
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Chapak.8bae0de0
K7GWTrojan ( 00528e801 )
Cybereasonmalicious.2b74ca
CyrenW32/StartSurf.AW.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.FZVG
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Chapak.edfz
BitDefenderApplication.Bundler.iStartSurf.DU
NANO-AntivirusRiskware.Win32.StartSurf.ewasbt
ViRobotAdware.Startsurf.1121280.JH
MicroWorld-eScanApplication.Bundler.iStartSurf.DU
TencentMalware.Win32.Gencirc.10b109a2
Ad-AwareApplication.Bundler.iStartSurf.DU
SophosGeneric PUA JE (PUA)
ComodoApplication.Win32.IStartSurf.BS@7lng48
BitDefenderThetaGen:NN.ZexaF.34294.eDW@aW6iQukk
TrendMicroTROJ_GEN.R002C0OKI21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.8de99ed2b74ca114
EmsisoftApplication.Bundler.iStartSurf.DU (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.aju
AviraHEUR/AGEN.1103322
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2345BE3
MicrosoftTrojan:Win32/Azorult!ml
SUPERAntiSpywarePUP.Bundler/Variant
GDataApplication.Bundler.iStartSurf.DU
AhnLab-V3Adware/Win32.StartSurf.R215690
Acronissuspicious
McAfeePacked-VV!8DE99ED2B74C
MAXmalware (ai score=100)
VBA32AdWare.StartSurf
MalwarebytesAdware.IStartSurf
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OKI21
RisingPUF.Prepscram!1.AEAF (CLASSIC)
YandexTrojan.GenAsa!vURxC3BvXlo
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GFGF!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan.Win32.Chapak.edfz?

Trojan.Win32.Chapak.edfz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment