Trojan

Trojan.Win32.Copak.kwmf removal tips

Malware Removal

The Trojan.Win32.Copak.kwmf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kwmf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

wpad.local-net

How to determine Trojan.Win32.Copak.kwmf?


File Info:

name: 0D412757BA5160ED7197.mlw
path: /opt/CAPEv2/storage/binaries/06ffeda5dcdf985e3f270999c64db256baaac75f4f7c8eb52907d76fd6eeea74
crc32: 9D8A8196
md5: 0d412757ba5160ed71975e74f2c9aef4
sha1: bae63a1d8163e98db94eb50e1268245a3e6984e0
sha256: 06ffeda5dcdf985e3f270999c64db256baaac75f4f7c8eb52907d76fd6eeea74
sha512: 4ab8bb64960fd1d909888342c698241635a77f2fefa77e51738e4b729610f7c1ea7a86aa6d15c7f4a5748522ce80e27469ac983453b1411dd7268460ad1ee79d
ssdeep: 49152:UOKQNVQlPQNVQZPQNVQlPQNVQV9aX9gQNVQlPQNVQZPQNVQlPQNVQx:eQNVQFQNVQZPQNVQFQNVQV9SyQNVQFQ4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DEC5DF5CB843C4B9F505B97B1ED0C7794EEBB33A6605397BB93C9814E0A523814E06BB
sha3_384: af2082a279eff8e62d7ae425f731d983a7f8d548d97fea0347f0ad98e77d8334fd7316f39c16d06da67f8ea045616c9e
ep_bytes: b88e6aad3481e9fea2720c89f968d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kwmf also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.0d412757ba5160ed
McAfeeArtemis!4FE1A6DD885F
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7ba516
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Iho3wxi-9880829-0
KasperskyTrojan.Win32.Copak.kwmf
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10ce6823
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
ZillyaTrojan.Injector.Win32.1274854
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Razy.900994 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bdaz
MaxSecureTrojan.Malware.121218.susgen
AviraHEUR/AGEN.1110715
Antiy-AVLTrojan/Generic.ASMalwS.334AA69
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34294.IwZ@aaoz!!o
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Injector!1.CD26 (CLASSIC)
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.kwmf?

Trojan.Win32.Copak.kwmf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment