Trojan

Trojan.Win32.Copak.movn removal

Malware Removal

The Trojan.Win32.Copak.movn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.movn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.movn?


File Info:

name: 9832E6D1E6555752C834.mlw
path: /opt/CAPEv2/storage/binaries/e78a151b2280d603c8e3daf7cba0c925050c848156066b8b6232e864b9bbd673
crc32: 15DD9950
md5: 9832e6d1e6555752c834b95ad1e01c32
sha1: 491077b5fe99da6e115636d1a3e0544c48933926
sha256: e78a151b2280d603c8e3daf7cba0c925050c848156066b8b6232e864b9bbd673
sha512: 3d970a5c0667932d45188723ad5bad5cd6095a173e09747a7e0e88e82c22c3404f0daa503c45293eac9df1d20e79f625db9bf0ecfe54d367a44d74ecd8bad347
ssdeep: 12288:ePmChXXMgVzkKMtUr463e9Uxs10VClc0YMW0:xChXXMgVzkm463eiqS0lJW0
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14A940122512343B7C5146C366A807C743AF77CDEA0025D279ED45B8FAF19CCA8A9F8B5
sha3_384: 3a4fa605cb513b0cb58b015228123edc471458f8ea51774c58323c25be5b6dadad093b630a80909ecb985d035ff8e5a3
ep_bytes: b84a82f95089db83ec04c70424d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.movn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.9832e6d1e6555752
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.2343561c
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9920386-0
KasperskyTrojan.Win32.Copak.movn
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Kryptik!1.D284 (CLOUD)
Ad-AwareGen:Variant.Razy.870640
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R03BC0DA922
McAfee-GW-EditionBehavesLike.Win32.Glupteba.gc
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.bnrr
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Glupteba
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD48F0
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34114.zuZ@aSwc1te
MAXmalware (ai score=85)
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R03BC0DA922
TencentWin32.Trojan.Copak.Hsry
eGambitUnsafe.AI_Score_88%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.1e6555
AvastWin32:Evo-gen [Susp]
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.movn?

Trojan.Win32.Copak.movn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment