Trojan

Trojan.Win32.Copak.kxkc malicious file

Malware Removal

The Trojan.Win32.Copak.kxkc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kxkc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.kxkc?


File Info:

name: BFBA6171B45736968E40.mlw
path: /opt/CAPEv2/storage/binaries/45a13e460541a9fbf3c661b86f0adac5510bc8b2bd47e222debd85adb333df99
crc32: ADB7AB5B
md5: bfba6171b45736968e403bae44d97ac0
sha1: cca713fb986296a9b4daa9b9ca631b8427ff8487
sha256: 45a13e460541a9fbf3c661b86f0adac5510bc8b2bd47e222debd85adb333df99
sha512: 6339fc86878e5e2eccc17cda67825c53c978310b0e484f192ff5af4b0b5663020781d83df742dd1a24e6aff536cbf7003f96dbd5a84213b5bfe0aaa7967d5f78
ssdeep: 12288:jRcPyhIHJfW8uhOIHJfW8dcN/x5IHJfW8uhOIHJfW8:FcWQJfnuhOQJfny/x5QJfnuhOQJfn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T102A412EA60C07B37F1C700BA0AC078463E3269E5D799E7989F0D86FC6951329BE57721
sha3_384: caaddda31a2db2abd6a14b2715fb6548d44bdf781430f3ed6f374200e4d7bbd25cd1bcf0362b0a076c70dd280413637d
ep_bytes: ba000000005021f15f4629f157415b81
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kxkc also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47472725
FireEyeTrojan.GenericKD.47472725
ALYacTrojan.GenericKD.47472725
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
BitDefenderTrojan.GenericKD.47472725
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.b98629
CyrenW32/Kryptik.DCC.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
KasperskyTrojan.Win32.Copak.kxkc
NANO-AntivirusTrojan.Win32.Copak.iqaqbd
RisingTrojan.Injector!1.C865 (CLASSIC)
Ad-AwareTrojan.GenericKD.47472725
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
ZillyaTrojan.Kryptik.Win32.3627086
TrendMicroPAK_Xed-10
EmsisoftTrojan.GenericKD.47472725 (B)
JiangminTrojan.Copak.whz
AviraHEUR/AGEN.1111440
Antiy-AVLTrojan/Generic.ASBOL.C686
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataTrojan.GenericKD.47472725
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369371
McAfeeGenericRXNW-AN!BFBA6171B457
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-10
YandexTrojan.Copak!O3ui6vp3usA
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Sality.AA
FortinetW32/Kryptik.HITO!tr
BitDefenderThetaGen:NN.ZexaF.34294.CmZ@aqxLbnk
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]

How to remove Trojan.Win32.Copak.kxkc?

Trojan.Win32.Copak.kxkc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment