Trojan

About “Trojan.Win32.Chapak.ewfm” infection

Malware Removal

The Trojan.Win32.Chapak.ewfm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.ewfm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
morasegio.ug
morasergio.ac.ug
apps.identrust.com
trqqwsad.site

How to determine Trojan.Win32.Chapak.ewfm?


File Info:

crc32: B2EFA12A
md5: 826d68f6e4a2c308e91aad81c8368443
name: upload_file
sha1: 66cffe0dc5cb3de1f5c0e754bc0e21e712e756f0
sha256: c686c7b2fff2ad2853c1d450d44fcf96ff3df67f34205b6b4e0352153893c924
sha512: a0220d1ad77ec7a0bf008ae275b9c66ce480ec55e1eacc582e40cd5d383dabd5ca2af1ae3b534a5bc135fd88beef2e52f2600b2604243a987660b46bf24f604c
ssdeep: 24576:7s50MSJZFvFsSss9TDdfLVMls50MMl+TZMs50MoEP80kKYfu:7s5SJbvFsSdjfyls5s+TZMs5oIkKYfu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: ui34z9f8j4i3r3wrfeef
FileVersion: 1.00
OriginalFilename: ui34z9f8j4i3r3wrfeef.exe
ProductName: Reesqwiejrfnsgsyng

Trojan.Win32.Chapak.ewfm also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.119443
FireEyeGeneric.mg.826d68f6e4a2c308
CAT-QuickHealTrojan.Chapak
McAfeeGenericRXMC-UT!826D68F6E4A2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005700601 )
BitDefenderGen:Variant.Bulz.119443
K7GWTrojan ( 005700601 )
Cybereasonmalicious.dc5cb3
InvinceaMal/Generic-S
CyrenW32/Trojan.IMCP-8165
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Chapak.ewfm
AlibabaTrojan:Win32/Chapak.599af844
ViRobotTrojan.Win32.Z.Injector.1318912
Ad-AwareGen:Variant.Bulz.119443
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader34.56760
TrendMicroTROJ_GEN.R002C0PJD20
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.Injector (A)
IkarusTrojan-Spy.Agent
JiangminTrojan.Chapak.lgg
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Injector
MicrosoftPWS:Win32/Fareit!ml
ArcabitTrojan.Bulz.D1D293
ZoneAlarmTrojan.Win32.Chapak.ewfm
GDataGen:Variant.Bulz.119443
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.119443
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesBackdoor.NanoCore
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.ENLK
TrendMicro-HouseCallTROJ_GEN.R002C0PJD20
RisingTrojan.Tiggre!8.ED98 (TFE:4:K0sbdD9urv)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ENLK!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.9df

How to remove Trojan.Win32.Chapak.ewfm?

Trojan.Win32.Chapak.ewfm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment