Trojan

Trojan.Win32.Chrop.ayq removal instruction

Malware Removal

The Trojan.Win32.Chrop.ayq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chrop.ayq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Likely virus infection of existing system binary

Related domains:

interestourflash.info

How to determine Trojan.Win32.Chrop.ayq?


File Info:

name: 45F0D5F1234FBB558C64.mlw
path: /opt/CAPEv2/storage/binaries/0436d6e4b8ce9284a34f95ab372a5aec5957e1f5fa9d2ee552cbed7386a335f5
crc32: 8A09B62B
md5: 45f0d5f1234fbb558c6428bde74d94ae
sha1: 5249dae0f42bc125b6f666aa16431654d4af824f
sha256: 0436d6e4b8ce9284a34f95ab372a5aec5957e1f5fa9d2ee552cbed7386a335f5
sha512: a68f4819010c449d2c1aa1eead257a86c5b2044a9ffd8050cfe8b7e20a2efaa8d9222fe5420353c136bce412a4092220750e203118a1c7955c7a20abbf844d8d
ssdeep: 49152:LcsQ6Q8iat+t7k/IwBA5pdzLbdN3h/vC5zp+j0unRORqc/LR/j:L1QT8iaMt7OBA5pdzLhNx/vAtA0unKLx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106E5F127B298653EC4AA27350573A42058FBB7ADF417BE1636F0C48DCF664C01E3EA65
sha3_384: 2deb32d676ca87dea574733df39ce3973bde9a05b71901a746713f52946cc88b622ce5377ccd549e59295f47b17090a6
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Copyright 2005 abSupport.com All Rights Reserved
FileDescription: abSupport UndeletePlus Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: abSupport UndeletePlus
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Chrop.ayq also known as:

McAfeeArtemis!45F0D5F1234F
MalwarebytesAdware.DownloadAssistant
AlibabaTrojan:Win32/Chrop.d1827738
ArcabitTrojan.Generic.D2D46F15
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Chrop.ayq
BitDefenderTrojan.GenericKD.47476501
MicroWorld-eScanTrojan.GenericKD.47476501
TencentWin32.Trojan.Chrop.Pfjk
Ad-AwareTrojan.GenericKD.47476501
TrendMicroTROJ_GEN.R03BC0WKO21
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.vc
FireEyeTrojan.GenericKD.47476501
EmsisoftTrojan.GenericKD.47476501 (B)
AviraTR/Redcap.iaxdw
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.47476501
AhnLab-V3Malware/Win.Generic.C4780047
VBA32Trojan.Chrop
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R03BC0WKO21
IkarusBackdoor.Win32.Bodelph
FortinetPossibleThreat.MU
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Win32.Chrop.ayq?

Trojan.Win32.Chrop.ayq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment