Trojan

What is “Trojan.Win32.Copak.amuwf”?

Malware Removal

The Trojan.Win32.Copak.amuwf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.amuwf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.amuwf?


File Info:

name: 14FD11DDAFBDB8102CB8.mlw
path: /opt/CAPEv2/storage/binaries/b411efdc4045e8635563fe6bbc20a48d5676dc2a6eb8d9c5c3eb6679029c7548
crc32: FEB2CCFD
md5: 14fd11ddafbdb8102cb8f68517b5f465
sha1: 15ddc378461d46337116f65dbc19d671684d5a5d
sha256: b411efdc4045e8635563fe6bbc20a48d5676dc2a6eb8d9c5c3eb6679029c7548
sha512: 98b996eb40bd2caa2f846bc0278e9139e4907308b1fd030c42b80870b0d33f83c0e35645b62de8052348b0a2872f28433547646fe61b938b963d06ed04c0dc7f
ssdeep: 12288:wQUXcuujAwFWfUnp4Nrbcol8zie973wEE:wQUXOAw5n2NxGA
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B184D0BBE3593A35C3F933BB1B4BF2D39E0076EC0056A5AE74F3918A5532510ADE4294
sha3_384: 7efed39bc8dd51d71a1587bdf5b7ea4e1a1232f394d03c10bad262f73b632ebdce4340cf964bb690da66285e1a5ad5b7
ep_bytes: 21f6eea3719f6a24747e63b5663c0b0f
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.amuwf also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Selfmod.4!c
MicroWorld-eScanTrojan.GenericKD.70705288
ClamAVWin.Packed.Razy-9873608-0
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!14FD11DDAFBD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.KryptikAGen.Win32.24032
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
AlibabaTrojan:Win32/Copak.2319ec4d
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D436E088
BitDefenderThetaGen:NN.ZexaF.36680.y4Z@aiNtz3j
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.amuwf
BitDefenderTrojan.GenericKD.70705288
NANO-AntivirusTrojan.Win32.Selfmod.ivuout
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
EmsisoftTrojan.GenericKD.70705288 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.123
VIPRETrojan.GenericKD.70705288
TrendMicroTROJ_GEN.R002C0DL523
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.auq
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.989
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.amuwf
GDataWin32.Trojan.PSE.11XGYE9
VaristW32/Trojan.NJGF-3047
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
VBA32Trojan.Khalesi
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DL523
TencentTrojan.Win32.Selfmod.kg
IkarusTrojan-Downloader.Win32.FakeAlert
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.8461d4
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Copak.amuwf?

Trojan.Win32.Copak.amuwf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment