Trojan

What is “Trojan.Win32.Chapak.ekea”?

Malware Removal

The Trojan.Win32.Chapak.ekea is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.ekea virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
whoer-vpn.net
a.tomx.xyz

How to determine Trojan.Win32.Chapak.ekea?


File Info:

crc32: ABFE7FDE
md5: ffa9fd16191a5324e4ce3afd9fd77630
name: setup_who.exe
sha1: 0a1fbdc8e33624e6ad29e200efb003e56bcf0d86
sha256: 2dfe9f3f4f44325e2bd4ea914b9e6262d9d88138b1f056ff2ccc8be7dfe16653
sha512: 70befe0bb7f3669adad8451e602c29578471327ed548275c7af40d09851f95608db6e96ec1be3c324663e7d6e7b05ebde5e6e00c839d48fed4efc4976c26744a
ssdeep: 24576:ss/PwVNshquOvL258aiTU/U0/yGbJ0HAMET9y32kmQmtXxBM1:sKPUqNOT2CPTIUKb2MymJQ83
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: omadmprc
CompanyName: verclsid
ProductName: CameraCaptureUI
ProductVersion: 696, 412, 890, 292
FileDescription: dstokenclean
OriginalFilename: SystemPropertiesDataExecutionPrevention.exe
Translation: 0x0000 0x04b0

Trojan.Win32.Chapak.ekea also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42885616
FireEyeGeneric.mg.ffa9fd16191a5324
ALYacTrojan.PasswordStealer.GenericKDS.33561107
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005633e81 )
BitDefenderTrojan.GenericKD.42885616
K7GWTrojan ( 005633e81 )
Cybereasonmalicious.8e3362
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.xnuaaOE9Dini
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCBDBO
Paloaltogeneric.ml
GDataTrojan.GenericKD.42885616
KasperskyTrojan.Win32.Chapak.ekea
APEXMalicious
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
Ad-AwareTrojan.GenericKD.42885616
SophosMal/Generic-S
DrWebTrojan.Siggen9.19239
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tc
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
EmsisoftTrojan.GenericKD.42885616 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.Banker.ClipBanker.nd
eGambitUnsafe.AI_Score_98%
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E61F0
AegisLabTrojan.Win32.Swisyn.lISn
ZoneAlarmTrojan.Win32.Chapak.ekea
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!FFA9FD16191A
MAXmalware (ai score=86)
VBA32BScope.Trojan.Tiggre
MalwarebytesSpyware.Oski
ESET-NOD32a variant of Win32/Packed.Themida.HJO
TencentWin32.Trojan.Chapak.Ehrt
IkarusTrojan.Win32.Themida
FortinetW32/Malicious_Behavior.VEX
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Chapak.ekea?

Trojan.Win32.Chapak.ekea removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment