Trojan

What is “Trojan.Win32.Copak.nhov”?

Malware Removal

The Trojan.Win32.Copak.nhov is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nhov virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.nhov?


File Info:

name: E10C8DC5E02029118858.mlw
path: /opt/CAPEv2/storage/binaries/340545fd6e0e0ba4d0b5fb7fd0d2d84ac7b061064375d61720e4522260b282ee
crc32: 749FC3BF
md5: e10c8dc5e020291188587fd1b3b32019
sha1: 2789fcfa5d66f37dca836bf1e0a0c892e31c205e
sha256: 340545fd6e0e0ba4d0b5fb7fd0d2d84ac7b061064375d61720e4522260b282ee
sha512: 81b2c066f2062c879953c7e82331983592790ffe0842fb86c91eab628d6881ea5ba4be58c1fdd3cae59d03239ed3dd151dcb05b02c8019fe72f9e055a7d88122
ssdeep: 3072:wXli0EATqvq5arOY5EjFkd43vrFyopK6ArFGzEOPFDZSu3DxkTk7v84vU6ysfm:oinzrOnF843JlVARYBTSu9rdvU1su
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10EF3D0919B9E2D22DF4D283081BE40DF4F6BC41EA11DDAD9F6010A40E7B8D5B5EC8E76
sha3_384: ec76c653ee000673a79ab12d9e220224c732ac7b1842af756d3957e253214fde97e2925803fc9e43171ceed8dbca4215
ep_bytes: bf661cab25bb0e2b4d5701d268d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nhov also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.e10c8dc5e0202911
McAfeeGlupteba-FTSD!E10C8DC5E020
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.900994
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.5e0202
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.nhov
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazpNZLMJ+tzNr81fhXHeyQVz)
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3323FE3
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wa
MAXmalware (ai score=84)
FortinetW32/Copak.AGMG!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.nhov?

Trojan.Win32.Copak.nhov removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment