Trojan

Trojan.Win32.Chapak.exnn removal instruction

Malware Removal

The Trojan.Win32.Chapak.exnn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.exnn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Chapak.exnn?


File Info:

crc32: 146CC1F5
md5: 089c02baf7793b1a80516ae9110ea1ce
name: 089C02BAF7793B1A80516AE9110EA1CE.mlw
sha1: c7efeed4dd77e9ba767f6b06c1f4aae0c68b6fd0
sha256: 6d2da2f5e9c0bdb662ec12ce1bb0515472f227b3a6ac9e148414d086c335c04f
sha512: 1ef581f454d388770d986d3e468c6eba5e8d2630827a9dc3727a9834e4cd11ae1aed62876e5a1cc3838a643795b208028c6b028790a76a9acd8a2e0a5301d591
ssdeep: 98304:boY5AOzlAonAMEjD4c9x1GkyJPaa4w18lgLCrG2B5XK2IbAwU67Q3/AoGPLeAG3:hxAfjD4c9raLgEH2BWpV7Q3YoGPFI1t
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x04ea

Trojan.Win32.Chapak.exnn also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.089c02baf7793b1a
CAT-QuickHealTrojan.Glupteba
Qihoo-360Win32/Trojan.c18
McAfeeGenericRXNG-QI!089C02BAF779
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00575bfb1 )
BitDefenderTrojan.GenericKD.36044330
K7GWTrojan ( 00575bfb1 )
CyrenW32/Trojan.VSZA-5752
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Chapak.exnn
AlibabaTrojan:Win32/Chapak.f98ee12b
AegisLabHacktool.Win32.ArchSMS.lsIq
MicroWorld-eScanTrojan.GenericKD.36044330
RisingTrojan.Kryptik!8.8 (TFE:5:V4nJcY6klTD)
Ad-AwareTrojan.GenericKD.36044330
EmsisoftTrojan.GenericKD.36044330 (B)
ComodoMalware@#14dr4hfa1t6or
F-SecureTrojan.TR/AD.GoCloudnet.ngrmt
TrendMicroRansom.Win32.STOP.USMANA621
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.ngrmt
MAXmalware (ai score=89)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225FE2A
ZoneAlarmTrojan.Win32.Chapak.exnn
GDataTrojan.GenericKD.36044330
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfaupMWTgG
ALYacTrojan.GenericKD.36044330
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIPB
TrendMicro-HouseCallRansom.Win32.STOP.USMANA621
TencentWin32.Trojan.Chapak.Glw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIFA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Chapak.exnn?

Trojan.Win32.Chapak.exnn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment