Trojan

About “Trojan.Win32.Copak.pyil” infection

Malware Removal

The Trojan.Win32.Copak.pyil is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.pyil virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.pyil?


File Info:

name: AC49B66CE0EBCAFD87AA.mlw
path: /opt/CAPEv2/storage/binaries/3cf57c43a702a7f07f3fd82191f13964adab8e21eb58c7bcdf2419d03af7236e
crc32: F77A22D1
md5: ac49b66ce0ebcafd87aaea1d77167bad
sha1: 7dd5a9609a196cb79bfad2906125f20e654a7829
sha256: 3cf57c43a702a7f07f3fd82191f13964adab8e21eb58c7bcdf2419d03af7236e
sha512: 6bb44b963a25c0d96a84d3d50616300e407a22ac439e46dc867fdf7fe0a62ee49298fbb7b7a03b612d4b7d9536fe86a86949b0eec87b25960917828c98d019a7
ssdeep: 12288:Zdn3UoQl+dQaaofMI22+9Xgi6BQhjGnCgHrs:Zdn3YlkQaDQ0isQxGnCgQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17C94018AE2CDB5DACEE8B4B45EBA51BC127F251FF966E123B006881706C1F4D40D5ADC
sha3_384: 9456af0a5d478db9d2ee1084d13e218068a24b95fbc8425c73dbe15306dd6e807b52ac290ab9887016adfcd76839357d
ep_bytes: b85d039b764181e9ba79204b83ec04c7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.pyil also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.ac49b66ce0ebcafd
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.ce0ebc
BitDefenderThetaGen:NN.ZexaF.34182.zuZ@aOhSZ5
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R03BC0DAU22
KasperskyTrojan.Win32.Copak.pyil
AlibabaTrojan:Win32/Copak.6da75196
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (CLOUD)
Ad-AwareGen:Variant.Razy.870640
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R03BC0DAU22
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.870640 (B)
APEXMalicious
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3514587
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataWin32.Trojan.Agent.DSAJSZ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGlupteba-FTSD!AC49B66CE0EB
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Downloader
TencentTrojan.Win32.Copak.wb
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.pyil?

Trojan.Win32.Copak.pyil removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment