Trojan

Trojan.Win32.Copak.mymr malicious file

Malware Removal

The Trojan.Win32.Copak.mymr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mymr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mymr?


File Info:

name: 318E9C77AA191207E4E9.mlw
path: /opt/CAPEv2/storage/binaries/89a9584b4cdf0ebeb6b186c240a57f09c1f93471c902c244ee98470d3fbdc44f
crc32: B24FD8FA
md5: 318e9c77aa191207e4e9a945c9cefd6b
sha1: f01d90ffd36814f4c4e4f8adab28f77801b20251
sha256: 89a9584b4cdf0ebeb6b186c240a57f09c1f93471c902c244ee98470d3fbdc44f
sha512: 6a620e0b50c0a8af91682a313d713ee7b74f75ce98e3d662b99492754d44b9e7c294da5217743fd05fb77905e9dfdaaffaf6211b2464431abf2490b357eeb529
ssdeep: 1536:W6SahSm2TdsgwnamIDEzCs85rFBgdPD88OkmAo1a2tzF4w2gU:yahSmuFTDEzaBFXjvOw/U
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13E83BF057AC1F15DC2AA433501FBDE770BBF0C63522E5A2BEAA797D1B4AB9193311312
sha3_384: 1b5f3c4f1a217def36ece698cdf9d590e8ca517b730ade21fb409568451ece7099232c2df638230b69c14b02c0517f61
ep_bytes: be2747aa5568d8854000b91bd335abb9
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mymr also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fuX@IfSC5Sd
FireEyeGeneric.mg.318e9c77aa191207
ALYacGen:Trojan.Heur.fuX@IfSC5Sd
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Trojan.Heur.fuX@IfSC5Sd
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.mymr
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10ce9037
Ad-AwareGen:Trojan.Heur.fuX@IfSC5Sd
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
EmsisoftGen:Trojan.Heur.fuX@IfSC5Sd (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.fuX@IfSC5Sd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3333CF7
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!318E9C77AA19
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (CLOUD)
IkarusTrojan.Win32.Injector
FortinetW32/Copak.AGMG!tr
BitDefenderThetaAI:Packer.4FFEE2691B
AVGWin32:Trojan-gen
Cybereasonmalicious.7aa191

How to remove Trojan.Win32.Copak.mymr?

Trojan.Win32.Copak.mymr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment