Trojan

Should I remove “Trojan.Win32.Copak.aanww”?

Malware Removal

The Trojan.Win32.Copak.aanww is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.aanww virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.aanww?


File Info:

name: F6BDA6AC867B259ACF9E.mlw
path: /opt/CAPEv2/storage/binaries/8fce63bb016ac8cbe622e1d99fe9fa305eb7a629424fa8dcd50bd5b173fb034f
crc32: 054575CF
md5: f6bda6ac867b259acf9ee16642eb257b
sha1: 5fdedff96d55c805c0ac9fb9f5e8109d8fce4fec
sha256: 8fce63bb016ac8cbe622e1d99fe9fa305eb7a629424fa8dcd50bd5b173fb034f
sha512: 3bd883dde4aee6ca4669a445ae10bb5e08de857c7caf66d55761a00128a054ff9bdc1018ed2ce379cb74200372059cc1a3c0f3d1a76af68c02dfc8170373dc3a
ssdeep: 49152:tnPTim2FhlgqeF+bq4TTow+lsghbyV8qa:tPGeshTWROV8qa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T124A5C08863B55947C967673BEC2DCB3F11466ABC6AA3DAB8304037EB79213D4A101F74
sha3_384: 1dcd75e1d751b6842587bb38f9191722fc9f996dbed75fa4e9eb1e5da03827a72d2a53ac4f1cdaa61a8e886c8b6c0fac
ep_bytes: f503a4dca56a205ba08b29ca22c14170
timestamp: 1975-06-24 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.aanww also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Khalesi.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.317678
FireEyeGeneric.mg.f6bda6ac867b259a
ALYacGen:Variant.Lazy.317678
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPREGen:Variant.Lazy.317678
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.2bd6fce5
K7GWTrojan ( 005a45ef1 )
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderThetaGen:NN.ZexaF.36250.i!Z@aSJ4gId
CyrenW32/Copak.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
ClamAVWin.Packed.Razy-9785185-0
KasperskyTrojan.Win32.Copak.aanww
BitDefenderGen:Variant.Lazy.317678
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:RATX-gen [Trj]
EmsisoftGen:Variant.Lazy.317678 (B)
F-SecureHeuristic.HEUR/Patched.Ren
DrWebTrojan.PackedENT.149
ZillyaTrojan.Kryptik.Win32.4194119
TrendMicroTROJ_GEN.R002C0DF323
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosTroj/Agent-BFEY
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.11YPVZ
GoogleDetected
AviraHEUR/Patched.Ren
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Kryptik.GIFY
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D4D8EE
ZoneAlarmTrojan.Win32.Copak.aanww
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.Generic.R565453
McAfeePacked-FJB!F6BDA6AC867B
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DF323
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.c867b2
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Copak.aanww?

Trojan.Win32.Copak.aanww removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment