Trojan

Trojan.Win32.Copak.bbzsm malicious file

Malware Removal

The Trojan.Win32.Copak.bbzsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.bbzsm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Copak.bbzsm?


File Info:

name: 646DC36B87EC76992D42.mlw
path: /opt/CAPEv2/storage/binaries/343e98d73a4aaf70f1af31d670675dbbeb392ea4676f8dc3dbd605cddb035031
crc32: 5419DA7F
md5: 646dc36b87ec76992d4234f1d0910642
sha1: 1fbff1a773e7b8ca4507c1a425a6465e5af83492
sha256: 343e98d73a4aaf70f1af31d670675dbbeb392ea4676f8dc3dbd605cddb035031
sha512: 32c4bd12cd35b96b1e697ef3669665089702f906137eae6a5379040a79263f6c36e813c714cbeef74b215d538297ab1f9e88e3bd0aa1929ea8f4dbea3b7b47e1
ssdeep: 12288:I8TBVowhSfaSU8/JjVDa/ZSoPDm3Xx/MCtjm:I6VowIaSU8/Pa/ZSoPDQ+ey
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13B3515192FC5D5B3CC07527F681EAE6240246DFC3612F7AE3381B57A3E26ED0472A964
sha3_384: 366c95feaec6c12e39de38b156b399dde59f6bb6288284ad876253cec05c3563ef278e793aecb0916c472a2df41dd656
ep_bytes: a801556ef868d1e9fd89d8787fc3b0c2
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.bbzsm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Selfmod.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.98449
ClamAVWin.Packed.Dridex-9860931-1
FireEyeGeneric.mg.646dc36b87ec7699
SkyhighBehavesLike.Win32.Generic.th
McAfeeTrojan-FVOQ!646DC36B87EC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Selfmod.Win32.1040
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
AlibabaTrojan:Win32/Copak.683eb0d9
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D18091
BitDefenderThetaGen:NN.ZexaF.36744.e9Z@aaiSldb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.bbzsm
BitDefenderTrojan.GenericKDZ.98449
NANO-AntivirusTrojan.Win32.Selfmod.iegusv
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.98449 (B)
F-SecureHeuristic.HEUR/AGEN.1369103
DrWebTrojan.PackedENT.216
VIPRETrojan.GenericKDZ.98449
TrendMicroTROJ_GEN.R002C0DAJ24
Trapminesuspicious.low.ml.score
SophosMal/Inject-GJ
IkarusTrojan-Downloader.Win32.FakeAlert
JiangminTrojan.Selfmod.mh
GoogleDetected
AviraHEUR/AGEN.1369103
Antiy-AVLTrojan/Win32.Kryptik.gify
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.bbzsm
GDataWin32.Trojan.PSE.11XGYE9
VaristW32/Trojan.MJSE-7842
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
VBA32Trojan.Copak
ALYacTrojan.GenericKDZ.98449
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAJ24
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.773e7b
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Copak.bbzsm?

Trojan.Win32.Copak.bbzsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment