Trojan

About “Trojan.Win32.Copak.ahmcq” infection

Malware Removal

The Trojan.Win32.Copak.ahmcq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ahmcq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.ahmcq?


File Info:

name: DF0354C03903EB9CCD10.mlw
path: /opt/CAPEv2/storage/binaries/2df5347a3bdd397da30ba6cfe4f4a3710180c71fd174cbbe2f80eee9830525e2
crc32: BFBCBFA9
md5: df0354c03903eb9ccd10fe3e1db20b76
sha1: 5e4f99b8390b5b4e6be45220a5581004c2f54e90
sha256: 2df5347a3bdd397da30ba6cfe4f4a3710180c71fd174cbbe2f80eee9830525e2
sha512: 76e1460a2fc34801deb6a952e382b91edb7ee5ec8dbd38c57dfc3e4abba930ba2f6b37c769c327a35658a490c8724ecd35a077c87b15cf3c842415c9c04f3eb9
ssdeep: 12288:g0dOsfgk0npM4dl0v5JHpS0wULVnMhysFjm+0npM4dl0v5JEe:JTfgkEM4dmv5Xf+hPEM4dmv52e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17E05CFC7B64CAE55C87D32731D393249A783B9BA2D29B91E24EC877F5653C3B418B210
sha3_384: 3a3c22c704f6006f624dd9c170b3dd3af2fae5443d158acf2e0ade55275e5f6d9df48062a259ba312cdf58868e652520
ep_bytes: eb389953bb612dd4beb014457cf37cff
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan.Win32.Copak.ahmcq also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.93801
FireEyeGeneric.mg.df0354c03903eb9c
SkyhighBehavesLike.Win32.RAHack.cc
ALYacGen:Variant.Symmi.93801
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Symmi.93801
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
BitDefenderGen:Variant.Symmi.93801
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.8390b5
BitDefenderThetaGen:NN.ZexaF.36792.043@aazQJtd
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyTrojan.Win32.Copak.ahmcq
AlibabaTrojan:Win32/Copak.6b428f17
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
F-SecureTrojan.TR/Patched.Ren.Gen
ZillyaTrojan.Kryptik.Win32.3766585
TrendMicroTROJ_GEN.R002C0DK223
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.93801 (B)
IkarusTrojan.Patched
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Razy.CD.gen!Eldorado
Antiy-AVLGrayWare/Win32.Kryptik.GIFQ
MicrosoftTrojan:Win32/Cerber.MPI!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Symmi.D16E69
ZoneAlarmTrojan.Win32.Copak.ahmcq
GDataWin32.Trojan.PSE.109W4IM
CynetMalicious (score: 100)
Acronissuspicious
McAfeeTrojan-FVOQ!DF0354C03903
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
VBA32Trojan.Khalesi
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DK223
TencentTrojan.Win32.Kryptik.gify
YandexTrojan.Agent!RRuFJhSd6qY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.ahmcq?

Trojan.Win32.Copak.ahmcq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment