Trojan

Trojan.Win32.Chapak.fbiq removal

Malware Removal

The Trojan.Win32.Chapak.fbiq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.fbiq virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com
mazoyer.ac.ug
mazooyaar.ac.ug

How to determine Trojan.Win32.Chapak.fbiq?


File Info:

crc32: E4377EC2
md5: be1aaef37143496d75cb83643ff63f8c
name: BE1AAEF37143496D75CB83643FF63F8C.mlw
sha1: 849a5bfbfdc16cad6c10edbaadcc4bad71756620
sha256: b594ae37dfb90a402bda0803680b455ababcc67e1add26f3c3f8f192d97dbe2a
sha512: 478d565fa97298583fc72debf544f556d0c113f51fc20ab626726dd6882401f06ba73f13772f1fed0d418c1ca4160e04b52949e82d97c189fc0848f1c6c8d737
ssdeep: 24576:waR0NC7TnVeuFVVo2f1sSu/3WxF0ZSFgazrw7bYOggrF0dz+QgAgL:waWNC7hLVVL1sX3WxKZKgW2hrKd7jE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: wanumesfrscsasfv2
FileVersion: 1.00
OriginalFilename: wanumesfrscsasfv2.exe
ProductName: Cesariusmegas

Trojan.Win32.Chapak.fbiq also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.62490
ALYacGen:Variant.Barys.102299
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Injector.bb6ce598
K7GWTrojan ( 00581be81 )
K7AntiVirusTrojan ( 00581be81 )
ESET-NOD32a variant of Win32/Injector.EQAA
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Chapak.fbiq
BitDefenderGen:Variant.Barys.102299
MicroWorld-eScanGen:Variant.Barys.102299
TencentWin32.Trojan.Barys.Pgcw
Ad-AwareGen:Variant.Barys.102299
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34126.8m0@a8AoB2D
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
FireEyeGeneric.mg.be1aaef37143496d
EmsisoftGen:Variant.Barys.102299 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Remcos.ARK!MTB
GridinsoftTrojan.Win32.Kryptik.dd!n
ArcabitTrojan.Barys.D18F9B
GDataGen:Variant.Barys.102299
McAfeeGenericRXPU-QT!BE1AAEF37143
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Stelega
MalwarebytesBackdoor.Remcos
PandaTrj/GdSda.A
RisingTrojan.Injector!1.C6AF (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FJIT!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Chapak.fbiq?

Trojan.Win32.Chapak.fbiq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment