Trojan

What is “Trojan.Win32.Kolovorot.ys”?

Malware Removal

The Trojan.Win32.Kolovorot.ys is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Kolovorot.ys virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Kolovorot.ys?


File Info:

name: 369273576E617FF4FC04.mlw
path: /opt/CAPEv2/storage/binaries/0c5f32580e4188ac84660967d0d27edae4908b0c9b53ef291ec54716d0b64064
crc32: E1058271
md5: 369273576e617ff4fc04124d5f80e5f2
sha1: d3cdb4d7322ec23c5043a567fe4e0617d17c66d8
sha256: 0c5f32580e4188ac84660967d0d27edae4908b0c9b53ef291ec54716d0b64064
sha512: 4a7cb888e1d876108461f142bdac2a4890f2cb762bb40840a2a1a37531acf08e63eddb2281de04dfb328e6535d3687d4c5fe58d7415724fc25a8d069c37242d3
ssdeep: 24576:HfqMeY3QBhoWYJgIDWAeTkzZ+RkFN/yKBUZZAFDrrqBh3SWgSklWXKBUZq:HneXoWS5ZRN/yKiZEDrKBST1WXKiZq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19685CF93F08280F2D92D153814B97B3BD67A691E0935DB8BA762FD765C32D82923710F
sha3_384: b3a068c548fbb0dccfa7042aa11c59797c3e62a61c3e18dfce939c55390c7b28b1a5fa6c97e4f7363651e7908de2d0f2
ep_bytes: 558bec6aff68106e540068b095470064
timestamp: 2015-09-21 10:32:53

Version Info:

0: [No Data]

Trojan.Win32.Kolovorot.ys also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kolovorot.lpUa
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PWSIME.3
FireEyeGeneric.mg.369273576e617ff4
CAT-QuickHealTrojan.Generic.2919
SkyhighBehavesLike.Win32.MultiDropper.th
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kolovorot.Win32.230
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Kolovorot.dd4b7e00
K7GWTrojan ( 005246d51 )
BaiduWin32.Trojan.FakeIME.d
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0RD124
AvastWin32:PUP-gen [PUP]
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyTrojan.Win32.Kolovorot.ys
BitDefenderGen:Heur.PWSIME.3
NANO-AntivirusTrojan.Win32.Kolovorot.fipsza
TencentTrojan.Win32.Kolovorot..wa
EmsisoftGen:Heur.PWSIME.3 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTool.Siggen.9393
VIPREGen:Heur.PWSIME.3
TrendMicroTROJ_GEN.R002C0RD124
Trapminemalicious.moderate.ml.score
SophosTroj/Agent-BDTR
Paloaltogeneric.ml
MAXmalware (ai score=87)
JiangminHeur:Backdoor/Blackhole
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/OnlineGames.HH.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.FlyStudio
KingsoftWin32.Trojan.Kolovorot.ys
MicrosoftBrowserModifier:Win32/Diplugem
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.PWSIME.3
ZoneAlarmTrojan.Win32.Kolovorot.ys
GDataWin32.Application.PSE.1OV7PVV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.QQPass.C134276
Acronissuspicious
VBA32BScope.Downloader.Snojan
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Darkmoon!8.B77 (TFE:5:eAfrX9vEJPN)
YandexTrojan.GenAsa!W9A0u0hyK0U
IkarusTrojan.Kolovorot
MaxSecureTrojan.Kolovorot.in
FortinetRiskware/FlyApplication
BitDefenderThetaGen:NN.ZexaF.36804.WvX@aOYGsIdb
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan.Win32.Kolovorot.ys?

Trojan.Win32.Kolovorot.ys removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment