Threat Database Trojans Trojan.Chapak.FI

Trojan.Chapak.FI

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,787
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: September 28, 2023
Last Seen: June 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Chapak.FI on your system indicates a potential security threat that requires immediate attention. This type of threat is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Chapak.FI?

Trojan.Chapak.FI is a type of malware that can infect your computer without your knowledge or consent. The term "Trojan" refers to a type of malware that disguises itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. Once inside, it can cause a range of problems, from stealing sensitive information to disrupting system performance.

How Trojan.Chapak.FI Operates

Malware like Trojan.Chapak.FI typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its creators or other malicious programs, allowing it to receive instructions or transmit stolen data. It may also attempt to spread to other parts of the system or to other computers, making it a significant threat to your security and privacy.

Symptoms of Infection

If your computer is infected with Trojan.Chapak.FI, you may notice a range of symptoms, including slow system performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice that your browser is being redirected to unfamiliar websites or that you're receiving unexpected pop-ups or ads. In some cases, you may not notice any symptoms at all, which is why regular scans and monitoring are essential for detecting and removing malware.

How to Remove Trojan.Chapak.FI

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan to ensure that the malware has been fully removed.

Conclusion

Removing Trojan.Chapak.FI from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable removal tools, you can help to ensure that your system is clean and secure. Remember to always be vigilant when downloading and installing software, and to regularly scan your system for malware to prevent future infections. By taking these steps, you can help to protect your computer and your personal data from the threats posed by malware like Trojan.Chapak.FI.

Analysis Report

General information

Family Name: Trojan.Chapak.FI
Signature status: No Signature

Known Samples

MD5: 02a95c32ba0d22c3c63d77ec79491924
SHA1: 3bb3dc3c7dfcdbeafd249aaa1d0223d9b9326ec3
SHA256: ACF611222DEDF92B6C9E37F600FBC7D0E575E49D45119FB65863F1EDE4A5BBEE
File Size: 6.79 MB, 6787128 bytes
MD5: e76aa6974a75830cabd942b1faf25aa1
SHA1: 084e8ff840004bc927d8e085cf36cdea8285bbab
SHA256: F41C011C1889D41E369FE8271E6A64245DF876EBA72495891381ED6728931019
File Size: 7.33 MB, 7330053 bytes
MD5: 2b8f5c2baddf8db47562a674f98ea849
SHA1: 50b6babfab02e51ab5d50b490315ce821af1c66b
SHA256: FD6AD175F0E07E57C7D57303B1B7C908926FF473E3CC6E2A6A09A2E0E13C6D36
File Size: 7.86 MB, 7863193 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 9.20
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2010 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 9.20

File Traits

  • 2+ executable sections
  • VirtualQueryEx
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\adobenotificationhelper.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\adobenotificationhelper.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\control surface.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\control surface.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\dns_sd.jar Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\dns_sd.jar Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity delay 2.nfo Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity delay 2.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity x-y-z controller.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity x-y-z controller.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\imagearray.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\imagearray.json Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\license.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\license.rtf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsnsp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsnsp.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsresponder.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsresponder.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc110_debugopenmp_arm.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc110_debugopenmp_arm.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc120_cxxamp_x86.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc120_cxxamp_x86.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\qp5blml9lnxw.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\qp5blml9lnxw.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\cofr.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\cofr.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity peak controller.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity peak controller.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity x-y controller.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity x-y controller.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\qt5svg.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\qt5svg.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\smpte-c.icc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\smpte-c.icc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\vrfauto.h Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\ bonjour.lnk Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\euroscaleuncoated.icc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\euroscaleuncoated.icc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity delay 2.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity delay 2.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity reeverb 2.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity reeverb 2.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\hl34tpxcm.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\hl34tpxcm.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\imagearray.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\imagearray.json Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\pcd.db Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\pcd.db Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\unzip32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\unzip32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\vrfauto.h Synchronize,Write Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

.\cOFR.exe
.\QP5BLML9lnxW.exe

Trending

Most Viewed

Loading...