Trojan

Trojan.Win32.Chapak.ayax (file analysis)

Malware Removal

The Trojan.Win32.Chapak.ayax is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.ayax virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

buburka.fun

How to determine Trojan.Win32.Chapak.ayax?


File Info:

crc32: C21010BF
md5: 89c86e75204974f7b5a55debff0a5fd6
name: 89C86E75204974F7B5A55DEBFF0A5FD6.mlw
sha1: 5f5144121287bd9865fae36ba21fb8dbd30f91a5
sha256: 58255da7f501da0646f4c0f764c754fdd5d3e228836ebcf9dd7d5d8714b088de
sha512: 4da49a68d234e415eaad842481c698d7431b8eb83591a6abc31a1cb8a9d41a58544462d8eeefd36d8ce04fbcacd3356166eb43461def4aa043a234d16242de2a
ssdeep: 3072:54oULxNMDInJHpmXptbhMhmId+6NJX2cXzcL31KZ7ItHHHwF0AWp5uLRllz:7ULxODYHI7h6x9JB+3cZQHHHcdLLRll
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: osdksdtgsdfg.exe
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
Translation: 0x0809 0x04b0

Trojan.Win32.Chapak.ayax also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24814
CynetMalicious (score: 100)
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.21828
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Chapak.2924970a
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.520497
CyrenW32/Kryptik.JW.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GLLG
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan.Win32.Chapak.ayax
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Chapak.fjcama
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Chapak.Edoa
Ad-AwareTrojan.Brsecmon.1
ComodoTrojWare.Win32.Ransom.Gandcrab.S@7wwdn1
BitDefenderThetaGen:NN.ZexaF.34050.ou0@a4Iq!rpi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.89c86e75204974f7
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.eg
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1102756
Antiy-AVLTrojan/Generic.ASMalwS.28885CD
MicrosoftRansom:Win32/Gandcrab.G!MTB
GDataWin32.Trojan-Ransom.GandCrab.U
AhnLab-V3Trojan/Win32.Agent.C2742968
Acronissuspicious
McAfeeTrojan-FQDF!89C86E752049
MAXmalware (ai score=100)
VBA32BScope.Trojan.Propagate
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingMalware.Obscure!1.A3BB (CLASSIC)
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLKY!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan.Win32.Chapak.ayax?

Trojan.Win32.Chapak.ayax removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment