Trojan

About “Trojan.Win32.Copak.ahsjr” infection

Malware Removal

The Trojan.Win32.Copak.ahsjr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ahsjr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.ahsjr?


File Info:

name: 5E38BBA466B2FB8D68AA.mlw
path: /opt/CAPEv2/storage/binaries/3f647cfccaf1cdc7dac7997498fe6a488d713a2614d7f1b791b804b21da3abf3
crc32: F4D4C9FC
md5: 5e38bba466b2fb8d68aa855ececefe01
sha1: 944b88d1fdd93a503a72e1499309b6c5b1365662
sha256: 3f647cfccaf1cdc7dac7997498fe6a488d713a2614d7f1b791b804b21da3abf3
sha512: b4bb0a43d6acf39aff0404ebd1d41b94f43d006f2184129eeeb6fd0e7e79ff410e0443e5768e270a995c07416a7ff1225b430517c2eee53d18de66024d062f0a
ssdeep: 12288:BkoZfvS4Pfc2/kjVDa/ZS4fD7HnhvMCtjW:CgnS4Pf/aa/ZS4fDDueC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13235F3191E551173CC06227D692EBE621421AC7C7A32F2E2338CB6763F21790B9577BE
sha3_384: e4f43bc0319111592872c08a5aff61ee026c6be9de7fcd68582b775cee440459d6f31bd2b12176e7f487f89f7b1e503e
ep_bytes: 3c12a2436c7b26c4699a2f55ebd047ef
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ahsjr also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98348
SkyhighBehavesLike.Win32.Generic.th
McAfeeTrojan-FVOQ!5E38BBA466B2
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.98348
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderTrojan.GenericKDZ.98348
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.1fdd93
ArcabitTrojan.Generic.D1802C
BitDefenderThetaGen:NN.ZexaF.36792.e9Z@ai!cyWb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyTrojan.Win32.Copak.ahsjr
NANO-AntivirusTrojan.Win32.Copak.jvibhg
ViRobotTrojan.Win.Z.Copak.1114113.ER
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SophosMal/Inject-GJ
F-SecureTrojan.TR/Crypt.XPACK.Gen2
ZillyaTrojan.Copak.Win32.167489
TrendMicroTROJ_GEN.R002C0DK323
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.5e38bba466b2fb8d
EmsisoftTrojan.GenericKDZ.98348 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/Zusy.EM.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik.GIFY
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.ahsjr
GDataWin32.Trojan.PSE.11YPVZ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5394145
Acronissuspicious
VBA32Trojan.Copak
ALYacTrojan.GenericKDZ.98348
TACHYONTrojan/W32.Selfmod
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DK323
TencentTrojan.Win32.Selfmod.ka
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.ahsjr?

Trojan.Win32.Copak.ahsjr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment