Trojan

Trojan.Win32.Copak removal tips

Malware Removal

The Trojan.Win32.Copak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak?


File Info:

name: 8EF3758E3E66158BC42C.mlw
path: /opt/CAPEv2/storage/binaries/5a5c020122d4ba61e65cad865b68003bdb661ee0539d7c7afca7589a63c26542
crc32: 27679DA3
md5: 8ef3758e3e66158bc42c323755281896
sha1: 45fae59a90675b53dce9fd61a871bc3081a5602c
sha256: 5a5c020122d4ba61e65cad865b68003bdb661ee0539d7c7afca7589a63c26542
sha512: 31039f082a925ccf9bc4b9231a2a55e8954468b6045e869c25de1f7d64d043264f9d9dff94e1d9c59bebd370650216e42d6d61c48b1cd66c3cb3411f839749c8
ssdeep: 3072:T1bksgPKiQmZoNV4AUXj/rfPy+IlLKIUHubYieVcoEWdViSlTRZ6tQa+NIvyM5nr:TprwKPnUXjDPE91G6YVVcCu2raTKM5MC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T120E3F18FB3490332C6810372B669D8E6D32EC4B9527E8095907AD54D039BF2953BB3E3
sha3_384: 570cb5b669ccea089f027abebdb7c409b77f18df5105da5ac1e73dfa062d8632eba610b39a77903030b4688ed6cc19ff
ep_bytes: 5589e5ba0000000089f789c989c089fb
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.866955
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Variant.Razy.866955
MalwarebytesTrojan.MalPack.Generic
ZillyaTrojan.CopakGen.Win32.1
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Razy.866955
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.jmY@a0gFINn
VirITWin32.NSPacker.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Berbew-10009572-0
KasperskyHEUR:Trojan.Win32.Copak.gen
RisingTrojan.Copak!8.12117 (TFE:1:vim7XzgLP1P)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Razy.866955
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.8ef3758e3e66158b
EmsisoftGen:Variant.Razy.866955 (B)
IkarusTrojan.Win32.Injector
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.a.995
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.DD3A8B
ZoneAlarmHEUR:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.FNZL9N
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2860595
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FFP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a90675
AvastWin32:Evo-gen [Trj]

How to remove Trojan.Win32.Copak?

Trojan.Win32.Copak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment