Spy Trojan

Should I remove “TrojanSpy:Win32/Chekafev.C”?

Malware Removal

The TrojanSpy:Win32/Chekafev.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Chekafev.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Behavioural detection: Injection (inter-process)
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanSpy:Win32/Chekafev.C?


File Info:

name: C5C74AC58EAC3627D447.mlw
path: /opt/CAPEv2/storage/binaries/2400d4093fd035ee9e56c313c8d1c53091bcec35fbbf409e1201836900db3e20
crc32: 1CC25B01
md5: c5c74ac58eac3627d447c94610b5c744
sha1: 80049843256bf7c349fe0eedc080f3c304bfbecb
sha256: 2400d4093fd035ee9e56c313c8d1c53091bcec35fbbf409e1201836900db3e20
sha512: c889931353b77c2f60256bae201daa570cb9159a67f3baf9ad96fa9932ed73194481add0273d05cfea7d8d0317b76b5875dd49c8119ac228794197928ebda5c1
ssdeep: 6144:RASvvlJKKiDCMmdwpGFEqqULirD2Ei/NjO50pqUl:RASnlJKKiDCMmdGGarm/f0+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA149D23DA044125F294477038A6DA752A766E3026F19E1FB344FF5A3B7A2D376B130B
sha3_384: dadc8857f568dc032d84cd473df018c5ed96c475760a0037640bc3fd2437acf1eaa6e054098b66923fed4f4ff106cdf2
ep_bytes: 68b01c4000e8eeffffff000000000000
timestamp: 2010-07-17 03:51:56

Version Info:

0: [No Data]

TrojanSpy:Win32/Chekafev.C also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.422079
Cylanceunsafe
ZillyaTrojan.Chekafev.Win32.5
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Variant.Barys.422079
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.58eac3
BaiduWin32.Trojan.StartPage.am
VirITTrojan.Win32.Generic.AOLH
CyrenW32/VB.BK.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB.PEH
APEXMalicious
ClamAVWin.Trojan.Staget-33
KasperskyTrojan.Win32.VB.apvl
AlibabaMalware:Win32/km_2f6.None
NANO-AntivirusTrojan.Win32.Staget.bstey
MicroWorld-eScanGen:Variant.Barys.422079
AvastWin32:Evo-gen [Trj]
RisingSpyware.Chekafev!8.1194 (TFE:3:nBPSxjEQOUH)
EmsisoftGen:Variant.Barys.422079 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.Generic.3106
VIPREGen:Variant.Barys.422079
TrendMicroTROJ_AGENT_005765.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c5c74ac58eac3627
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Staget.io
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VB.gic
MicrosoftTrojanSpy:Win32/Chekafev.C
XcitiumTrojWare.Win32.Spy.Chekafev.AF@4qdt6w
ArcabitTrojan.Barys.D670BF
ZoneAlarmTrojan.Win32.VB.apvl
GDataWin32.Trojan.PSE.13LF282
GoogleDetected
AhnLab-V3Trojan/Win32.Staget.C43172
Acronissuspicious
McAfeeBackDoor-EVE.a
MAXmalware (ai score=100)
VBA32BScope.Trojan.KillProc
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/StartPage.DAW
TrendMicro-HouseCallTROJ_AGENT_005765.TOMB
TencentMalware.Win32.Gencirc.13d1143f
YandexTrojan.GenAsa!qewpuZKqGL8
IkarusTrojan-PWS.Win32.Agent
MaxSecureTrojan.Staget.eg
FortinetW32/Staget.EG!tr
BitDefenderThetaAI:Packer.3DE856CF20
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:Win32/Chekafev.C?

TrojanSpy:Win32/Chekafev.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment