Trojan

What is “Trojan:Win32/Chapak.C”?

Malware Removal

The Trojan:Win32/Chapak.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Chapak.C virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Anomalous binary characteristics

How to determine Trojan:Win32/Chapak.C?


File Info:

crc32: B524EABA
md5: 0d9459c9bf9dee9c89c72599df2a74f8
name: 0D9459C9BF9DEE9C89C72599DF2A74F8.mlw
sha1: ca165f172295a308f13aca43507001bf871feb01
sha256: 745568ff48abcffbe02de9246e249549ebbfa3d5bf9d269b6eed550d1e4fb911
sha512: ce9f2abc981b37db21962dbc0dbec865963b30aced8f0e7634277c69d1edc3b44083261460eb028d58b04c2dd6b838f39c5e4b3f7c8e0310da0efdb5c4b15302
ssdeep: 3072:ePACH0VQkWZ67j82BJwV5HymgNVug2hgGGzCL5lxpuBb0ybUuUQfexG0h8nD+jRF:eJZWT1KgnzCL5lxybdwGeAqgA1qu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Chapak.C also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00532fcf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Cloxer.A06
ALYacTrojan.Ransom.GandCrab.Gen.2
MalwarebytesTrojan.MalPack
ZillyaTrojan.GandCrypt.Win32.264
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00532fcf1 )
Cybereasonmalicious.9bf9de
CyrenW32/S-94c882be!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GHFR
APEXMalicious
AvastWin32:Agent-BCIA [Trj]
ClamAVWin.Packed.Phorpiex-9810805-1
BitDefenderTrojan.Ransom.GandCrab.Gen.2
NANO-AntivirusTrojan.Win32.GandCrypt.fcyqwl
ViRobotTrojan.Win32.GandCrab.Gen.A
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
TencentMalware.Win32.Gencirc.10c93876
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
ComodoTrojWare.Win32.Magniber.FGH@7nyazg
BitDefenderThetaGen:NN.ZexaF.34670.lyX@a4DdT@oi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeGeneric.mg.0d9459c9bf9dee9c
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
JiangminTrojan.GandCrypt.ds
AviraHEUR/AGEN.1103299
MicrosoftTrojan:Win32/Chapak.C
AegisLabTrojan.Win32.GandCrypt.j!c
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataTrojan.Ransom.GandCrab.Gen.2
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeeGenericRXFP-BC!0D9459C9BF9D
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
RisingTrojan.Kryptik!1.B2AC (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:Agent-BCIA [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Chapak.HwoCEpsA

How to remove Trojan:Win32/Chapak.C?

Trojan:Win32/Chapak.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment