Trojan

Trojan.Win32.Copak.kxso malicious file

Malware Removal

The Trojan.Win32.Copak.kxso is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kxso virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kxso?


File Info:

name: A299DEF0E666785F1DC3.mlw
path: /opt/CAPEv2/storage/binaries/d4d236a6b55a46b05df7367bd1167a9b55d41a29d279c1acd9873153acb18e2e
crc32: FCF68E6D
md5: a299def0e666785f1dc3a57e11419a3f
sha1: f1edc38215f9eff808f4d8589d18d9bddcb9d629
sha256: d4d236a6b55a46b05df7367bd1167a9b55d41a29d279c1acd9873153acb18e2e
sha512: 5090f8d79d57f3ac76a4dd28d69dcc1777fbd1950ed8821e0986a76979bb1428bfed971e7035ea239ffbe9bc94816404b14e7981ca47e121636efdaba655f44d
ssdeep: 49152:Agcq+AEzEskdfFUWDC7JKLte3GK4T0TZw:PwEskvTm7JKL03G1gF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19F7533C9C127ECB5FC2636BA23949C8768258586E5772063E4FB11F7C77B184E4A7328
sha3_384: b78cd90ff39b6b8d0a1d72edf33cd218d866d47d797c8f3aa90b94169282e51458e350f29b3cab82fd948d39a51ad8ce
ep_bytes: b90000000083ec0489142481e84a7de7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kxso also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
FireEyeGeneric.mg.a299def0e666785f
MalwarebytesTrojan.Injector
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
K7AntiVirusTrojan ( 0057ffc71 )
BitDefenderThetaGen:NN.ZexaF.34062.InZ@aerBDlm
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKS21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.kxso
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
ComodoPacked.Win32.MUPX.Gen@24tbus
TrendMicroTROJ_GEN.R002C0DKS21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-R
IkarusTrojan.Win32.Injector
JiangminRiskTool.BitCoinMiner.arii
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C690
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366157
McAfeeGenericRXAA-FA!A299DEF0E666
VBA32Trojan.Packed
CylanceUnsafe
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.215f9e
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Copak.kxso?

Trojan.Win32.Copak.kxso removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment