Trojan

Should I remove “Trojan.Win32.Chapak.ewvw”?

Malware Removal

The Trojan.Win32.Chapak.ewvw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.ewvw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

pimpmychrome.com
ip-api.com

How to determine Trojan.Win32.Chapak.ewvw?


File Info:

crc32: F92AA067
md5: f0403b76ce91b0b51b61d4b57993603f
name: F0403B76CE91B0B51B61D4B57993603F.mlw
sha1: e24c5e85ca84759762250f81fc126be434b26d1d
sha256: bc1f1478ce900528834df2c37730991b230f4744e0fc45bb7349a6f6a5f4513c
sha512: 1280cb24f473d0172711c1e8ba70cb2f640f214e491b363c36d3add884c5b0440c8326ffcd59cc11e80c92e41a668a64f55262071b5ccdc1035e56b5e4f6a217
ssdeep: 12288:uQ8A2Gg75WuGjU63SWy4mDUvjWwLTuZVvoeJ+ir:B8AFS5uS2cU7WwL6+O
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019, matrix
InternalName: reboot.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0841 0x04bb

Trojan.Win32.Chapak.ewvw also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71941
FireEyeGeneric.mg.f0403b76ce91b0b5
CAT-QuickHealTrojan.Chapak
Qihoo-360Win32/Trojan.d38
ALYacTrojan.GenericKDZ.71941
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00574bc31 )
BitDefenderTrojan.GenericKDZ.71941
K7GWTrojan ( 00574bc31 )
BitDefenderThetaGen:NN.ZexaF.34700.HmKfaSIfbDd
CyrenW32/Bulta.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Generic-9811131-0
KasperskyTrojan.Win32.Chapak.ewvw
AlibabaTrojan:Win32/Chapak.42061b23
NANO-AntivirusTrojan.Win32.Chapak.idxuyr
ViRobotTrojan.Win32.Z.Kryptik.543744.Z
AegisLabTrojan.Win32.Chapak.4!c
Ad-AwareTrojan.GenericKDZ.71941
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2xkvrb1kjja1k
F-SecureTrojan.TR/Crypt.Agent.gykgj
DrWebTrojan.DownLoader36.28539
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03BC0DLH20
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.gykgj
KingsoftWin32.Troj.Chapak.ew.(kcloud)
MicrosoftTrojan:Win32/Coroxy.MR!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D11905
ZoneAlarmTrojan.Win32.Chapak.ewvw
GDataTrojan.GenericKDZ.71941
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358090
Acronissuspicious
McAfeeRDN/Generic Dropper
MAXmalware (ai score=100)
VBA32BScope.Exploit.Shellcode
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIGQ
TrendMicro-HouseCallTROJ_GEN.R03BC0DLH20
RisingTrojan.Ransom.GlobeImposter!1.AF70 (TFE:5:bYXJg1YG3DR)
YandexTrojan.GenAsa!A3rOJaxYS2w
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Chapak.ewvw?

Trojan.Win32.Chapak.ewvw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment