Trojan

What is “Trojan.Win32.Copak.bghih”?

Malware Removal

The Trojan.Win32.Copak.bghih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.bghih virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Copak.bghih?


File Info:

name: 81198389421516EF54F6.mlw
path: /opt/CAPEv2/storage/binaries/e05bd42da8e809cb7bb2338eaa0113cdd8021e626c5cba1b30d07c021572df78
crc32: 44CEA7E0
md5: 81198389421516ef54f6d9ac7abbae48
sha1: d8916fd925976d12abc633b3161dcf59ad759ed0
sha256: e05bd42da8e809cb7bb2338eaa0113cdd8021e626c5cba1b30d07c021572df78
sha512: 560f46715a34833b33f83d2886a4bbee0544635ead4f71e168d40b95c44b0e80699c059759f2253b5d715dea3cd8b52198657c0cbb45497e51b072a8aaa1e0db
ssdeep: 49152:Bq/eDm7gOuCpq6+Fb0rq8g4HbExL5ISJSK6naPsD0gKQZ:oUFHFsqYHQQSJSKPF7i
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D6A5F1582BAA6547D1A7BE3BEC5C85B97031683E3FE2C63F3005399D7452FA86206734
sha3_384: bbf4d39c1029f56459d58aa827ba49d04d54080a717edd948746d900c38d6b10c86ce6d85f5c834e973df35610b8651c
ep_bytes: e50c3cb5b565b832b084b1a332ced919
timestamp: 1976-11-05 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.bghih also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
DrWebTrojan.PackedENT.216
MicroWorld-eScanTrojan.GenericKDZ.104110
FireEyeGeneric.mg.81198389421516ef
SkyhighBehavesLike.Win32.Ctsinf.vc
McAfeeTrojan-FVOQ!811983894215
Cylanceunsafe
ZillyaTrojan.Copak.Win32.186338
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
AlibabaTrojan:Win32/Copak.4a6309bd
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.925976
BitDefenderThetaGen:NN.ZexaF.36744.a!Z@aS26mDk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
APEXMalicious
ClamAVWin.Packed.Malwarex-9792170-0
KasperskyTrojan.Win32.Copak.bghih
BitDefenderTrojan.GenericKDZ.104110
NANO-AntivirusTrojan.Win32.Selfmod.ijdkxa
AvastWin32:RATX-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.104110 (B)
GoogleDetected
F-SecureTrojan.TR/Kryptik.hcesb
VIPRETrojan.GenericKDZ.104110
TrendMicroTROJ_GEN.R049C0DAT24
Trapminemalicious.high.ml.score
SophosTroj/Agent-BFEY
IkarusTrojan-Downloader.Win32.FakeAlert
GDataWin32.Trojan.PSE.11XGYE9
JiangminTrojan.Selfmod.gpm
VaristW32/Trojan.MJSE-7842
AviraTR/Kryptik.hcesb
Antiy-AVLTrojan/Win32.Kryptik.gify
KingsoftWin32.HeurC.KVMH008.a
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D196AE
ZoneAlarmTrojan.Win32.Copak.bghih
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
ALYacTrojan.GenericKDZ.104110
MAXmalware (ai score=81)
VBA32Trojan.Copak
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0DAT24
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
YandexTrojan.Copak!TnQUCa2giI0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.bghih?

Trojan.Win32.Copak.bghih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment