Trojan

What is “Trojan.Win32.Copak.mhyd”?

Malware Removal

The Trojan.Win32.Copak.mhyd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mhyd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mhyd?


File Info:

name: 63855327D5A87A66F97D.mlw
path: /opt/CAPEv2/storage/binaries/1c27b6108bd3830cc3f100ba2ffbcddef737819a85e94e4744b2ebdf49baa21b
crc32: D6A3DF51
md5: 63855327d5a87a66f97d62fcc2fe70cf
sha1: 56c8a74b0ee7453444dcd756c541a9a15ae64319
sha256: 1c27b6108bd3830cc3f100ba2ffbcddef737819a85e94e4744b2ebdf49baa21b
sha512: dacc74783e1c02990c44c3d107f4cd42870e1956a962b096f0a1aadaee9636a3dd1ade9decc64607069834d877a12e01821f90c8278d82a615a44a85fbfde4cd
ssdeep: 3072:NNAFHgTb7gGphjZ9r1d5KRQErbv0QzcMjqzOPuL2buwbejj3:86P7g4hZpOQErbv3ceQOPowij3
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10BF3CF1C0B42D13AE229B67B5A92C1C1C4B991EF0C3768FFB2CA5D51AB514CCB5BE4B4
sha3_384: 0d590ab3f0cf792bb2c81747d390ae96ca86ec8b3b46c9f0efd034c889c1481b98155d7e3a8c1a4ecec5726bff0ad8a3
ep_bytes: bfc2236a8581ea1ca688a568d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mhyd also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
McAfeeGenericRXGJ-XZ!0B097E5D8B1A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7d5a87
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.mhyd
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfc566
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
FireEyeGeneric.mg.63855327d5a87a66
EmsisoftGen:Variant.Razy.865537 (B)
GDataGen:Variant.Razy.865537
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33BB675
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazon/Iesw2lLNIVbibihTAgU)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.mhyd?

Trojan.Win32.Copak.mhyd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment