Trojan

About “Trojan.Win32.Chapak.eftx” infection

Malware Removal

The Trojan.Win32.Chapak.eftx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan.Win32.Chapak.eftx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Chapak.eftx?


File Info:

crc32: BC762E90
md5: 290e97907e5be8ea72178414762cd846
name: 5.exe
sha1: 525dcbd6bbec8922b16172a497cab98e41da8086
sha256: 8e0583c73e92efde9f026bd911879c83f61c3dfab853d283a3073defe33503bc
sha512: e81f5d73c409ceeb67e855cb26a8a25385439131652c5d03a178722ade2df9bb39d2a738274b0b8209f19d4ce2abc377892bbbe5b1ec11c0c1164d096e5f77a6
ssdeep: 12288:G2Rd5yMwP2HrgrsPNlryR0uud7CrIFfHr:G2Ry0HE4PrWVUCKj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0219 0x04e4

Trojan.Win32.Chapak.eftx also known as:

MicroWorld-eScanGen:Variant.Graftor.684274
McAfeeRDN/Generic BackDoor
K7AntiVirusTrojan ( 003c36381 )
K7GWTrojan ( 003c36381 )
CrowdStrikewin/malicious_confidence_90% (W)
ESET-NOD32a variant of Win32/Kryptik.GYTN
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Chapak.eftx
BitDefenderGen:Variant.Graftor.684274
RisingBackdoor.Predator!8.6DF3 (TFE:5:6NFZc5SJZfN)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/Crypt.Agent.mndcq
DrWebTrojan.Siggen8.58010
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FortinetW32/Kryptik.GYTM!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.290e97907e5be8ea
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
WebrootW32.Malware.Gen
MAXmalware (ai score=100)
ArcabitTrojan.Graftor.DA70F2
ZoneAlarmTrojan.Win32.Chapak.eftx
MicrosoftBackdoor:Win32/Predator.J!MTB
AhnLab-V3Trojan/Win32.Agent.R300968
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
ALYacGen:Variant.Graftor.684274
Ad-AwareGen:Variant.Graftor.684274
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H09KP19
IkarusWin32.Outbreak
GDataGen:Variant.Graftor.684274
BitDefenderThetaGen:NN.ZexaF.32515.Du0@ay1sUxm
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.6bbec8
AvastWin32:PWSX-gen [Trj]
Qihoo-360HEUR/QVM10.2.7624.Malware.Gen

How to remove Trojan.Win32.Chapak.eftx?

Trojan.Win32.Chapak.eftx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment