Trojan

Trojan.Win32.Copak.ahels information

Malware Removal

The Trojan.Win32.Copak.ahels is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ahels virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.ahels?


File Info:

name: 7AC2EE1FC1104FDBADA5.mlw
path: /opt/CAPEv2/storage/binaries/7f16a3f9625162ae4b0f7909816e4b7e2ede893debc2b50e0ce1c36f250b19e1
crc32: 8ACCA0FE
md5: 7ac2ee1fc1104fdbada56dd45f4e0678
sha1: 2ebd54e27f73e43e25e6426b621967b41d79b770
sha256: 7f16a3f9625162ae4b0f7909816e4b7e2ede893debc2b50e0ce1c36f250b19e1
sha512: 8c78ddb2cade96d4cdad9f136d76694734e79705da2371edcb01c6c495aaa1a48a82d3ed471957fcb5504c3cabdb510295e811feb436e76ec70258bbfb880909
ssdeep: 12288:5q+Ch0iiFxmIklA/Rt4BidMn0O6HNjVDa/ZSoPDm3Xx/MCtjW:QVeiiFxclAT4BidMncTa/ZSoPDQ+ei
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C855BE9D0E91C473CC06167E6A2FEEE655116F2C62B2BA35338177FE3FA12AD4416720
sha3_384: b83e2180e3b508ac01f44b6f03ec4603cfef3d46e32ab347aa0db2ab664e7b985666be3feaccf48912b555b3450b48fa
ep_bytes: d4b7055f84de81d8813f88490375e0f3
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ahels also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98449
FireEyeGeneric.mg.7ac2ee1fc1104fdb
SkyhighBehavesLike.Win32.Generic.tm
ALYacTrojan.GenericKDZ.98449
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.2818800
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderTrojan.GenericKDZ.98449
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.27f73e
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.ahels
NANO-AntivirusTrojan.Win32.Copak.jvibhg
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SophosMal/Inject-GJ
F-SecureTrojan.TR/Glupteba.zlvrc
DrWebTrojan.Siggen21.55147
VIPRETrojan.GenericKDZ.98449
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKDZ.98449 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Zusy.EM.gen!Eldorado
AviraTR/Glupteba.zlvrc
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik.GIFY
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D18091
ZoneAlarmTrojan.Win32.Copak.ahels
GDataWin32.Trojan.PSE.11YPVZ
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
McAfeeTrojan-FVOQ!7AC2EE1FC110
TACHYONTrojan/W32.Selfmod
DeepInstinctMALICIOUS
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfmod.ka
YandexTrojan.Kryptik!oy5760fjUqc
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36792.q9Z@aaiSldb
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.ahels?

Trojan.Win32.Copak.ahels removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment