Trojan

Trojan.ChapakRI.S24673318 removal tips

Malware Removal

The Trojan.ChapakRI.S24673318 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ChapakRI.S24673318 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.ChapakRI.S24673318?


File Info:

name: 3B341BECB3C071368B45.mlw
path: /opt/CAPEv2/storage/binaries/25adc1ea043bd4b1895dfc0900330a2ff5caaea0acfae0fdb130ec19a689ccca
crc32: 1E1B0942
md5: 3b341becb3c071368b45e5308fa85632
sha1: 2f9650cc443139ac7652239dcc31193504d09983
sha256: 25adc1ea043bd4b1895dfc0900330a2ff5caaea0acfae0fdb130ec19a689ccca
sha512: 5b9d9c418fcd01184b7bc38e182d43652171bea0e1848092d263aed0e41bce5a753ed29248470f00ed96ffb11aa9a1e60a8caae4e1a39265fb0abc2424e109bf
ssdeep: 6144:Oa2nLkjmydub+vf2PmzgQOdGmUFajRE11xB7QWA:0nLfydBe+Ud99jREzxB4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB748D00BAA0C035F5F316F849BA93ACB93E7EA15B6950CF52E516EE06346E0EC31757
sha3_384: 5b4d9bcad8ccc4e81df9e7b104f228c7e11870579e710b6771d1ce686fac0dfae6ee2236cb1fb39d256bc53b7729dda5
ep_bytes: 8bff558bece8d6970000e8110000005d
timestamp: 2021-02-22 19:06:04

Version Info:

Translations: 0x0452 0x0011

Trojan.ChapakRI.S24673318 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.79130
CAT-QuickHealTrojan.ChapakRI.S24673318
McAfeePacked-GDT!3B341BECB3C0
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
BitDefenderTrojan.GenericKDZ.79130
K7GWTrojan ( 005690671 )
Cybereasonmalicious.c44313
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FOO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMZX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9903298-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
AlibabaTrojan:Win32/Crypter.5a5d2aed
RisingTrojan.Kryptik!1.D9FE (CLOUD)
Ad-AwareTrojan.GenericKDZ.79130
SophosMal/Generic-S + Troj/Krypt-DY
F-SecureHeuristic.HEUR/AGEN.1242281
DrWebTrojan.Siggen15.28834
ZillyaTrojan.Kryptik.Win32.3602207
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.3b341becb3c07136
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Chapak.ora
AviraHEUR/AGEN.1242281
Antiy-AVLTrojan/Generic.ASMalwS.34C52D7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Crypter!MTB
ArcabitTrojan.Generic.D1351A
GDataTrojan.GenericKDZ.79130
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GDT.R446567
Acronissuspicious
ALYacTrojan.GenericKDZ.79130
MAXmalware (ai score=80)
VBA32Trojan.Chapak
CylanceUnsafe
PandaTrj/Genetic.gen
YandexTrojan.Chapak!fXJmx86yUGA
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.ChapakRI.S24673318?

Trojan.ChapakRI.S24673318 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment