Trojan

Should I remove “Trojan.Win32.Chapak.ediv”?

Malware Removal

The Trojan.Win32.Chapak.ediv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.ediv virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Chapak.ediv?


File Info:

crc32: 516C308A
md5: a1ff7975810b6a9bf046f6a4782bc934
name: setup.exe
sha1: e60b9301d29f640f8eb671d97fd63e2eb3298eca
sha256: c5c067473ed4bdd85dcd133a73a5423971d2f8da5c63490ec0a8b774d7b341fc
sha512: a9be74ada359a353eaa0d73529abb7d9db564b93e165f2f9bce7ab5e52d09a2a3a515860f6c950a71d86d5616c1e6f69ca3d00d155ce68e90777e9c91662be7b
ssdeep: 24576:Mu6Jx3O0c+JY5UZ+XC0kGso/WahCJ8nLCaSWYI:WI0c++OCvkGsUWahlYI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 My Privacy Tools, Inc.
FileVersion: 6.0.0.605
CompanyName: My Privacy Tools, Inc.
Comments: This installation was built with Inno Setup.
ProductName: Hide My IP
ProductVersion: 6.0.0.605
FileDescription: Hide My IP Setup Program
Translation: 0x0000 0x04b0

Trojan.Win32.Chapak.ediv also known as:

MicroWorld-eScanTrojan.GenericKD.42204966
CAT-QuickHealTrojan.Predator
McAfeeArtemis!A1FF7975810B
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055b7401 )
BitDefenderTrojan.GenericKD.42204966
K7GWTrojan ( 0055b7401 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTROJ_GEN.R004C0DKG19
CyrenW32/Trojan.FYMG-4510
SymantecPacked.Generic.548
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42204966
KasperskyTrojan.Win32.Chapak.ediv
AlibabaTrojan:Win32/Chapak.96c3a0f9
NANO-AntivirusTrojan.Win32.AutoIt.ghxqbn
ViRobotTrojan.Win32.Z.Autoit.1263184
AegisLabTrojan.Win32.Autoit.4!c
RisingTrojan.Obfus/Autoit!1.BD7E (CLASSIC)
Ad-AwareTrojan.GenericKD.42204966
SophosMal/Generic-S
ComodoMalware@#31gwbjpq2e4mh
F-SecureTrojan.TR/Autoit.zuzft
DrWebTrojan.AutoIt.631
Invinceaheuristic
McAfee-GW-EditionTrojan-AitInject.aq
FireEyeTrojan.GenericKD.42204966
EmsisoftTrojan.GenericKD.42204966 (B)
IkarusTrojan.Autoit
JiangminTrojan.Script.akpv
AviraTR/Autoit.zuzft
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D283FF26
ZoneAlarmTrojan.Win32.Chapak.ediv
MicrosoftTrojan:Win32/Predator.BC!rfn
AhnLab-V3Win-Trojan/Autoinj03.Exp
Acronissuspicious
VBA32Trojan.Chapak
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.AutoIt.TT
TrendMicro-HouseCallTROJ_GEN.R004C0DKG19
eGambitPE.Heur.InvalidSig
FortinetAutoIt/Injector.EQU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.a69

How to remove Trojan.Win32.Chapak.ediv?

Trojan.Win32.Chapak.ediv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment