Trojan

Trojan.Win32.Copak.pyme removal

Malware Removal

The Trojan.Win32.Copak.pyme is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.pyme virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.pyme?


File Info:

name: C2E4B969B47A8ACFBCEB.mlw
path: /opt/CAPEv2/storage/binaries/aed4f470bc396de20a93dce1a862fe1b52defe624aaab47e4080e8ffd1ed54db
crc32: D4665AD1
md5: c2e4b969b47a8acfbceba677260155b9
sha1: bb3b95a891d2fb3b06450720290b78b7e99a92c6
sha256: aed4f470bc396de20a93dce1a862fe1b52defe624aaab47e4080e8ffd1ed54db
sha512: 8d50c77fefef85087747b4058139dd9006bb3e63fbcb49b12ccc36588652233386a29ce73874b4ad51334be2ad8df71e9b97b2bb5dc3178a73c1b1a31dffc63d
ssdeep: 6144:qCbXNs+FyP0aoAjI1h9SMCICbXNs+FyPh:qyzE8aVI1nnyzE5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11034D04BC45C8C47EE264F30D124F98A427A156FBDE03F2A9DA8A400F1FD592F159EAD
sha3_384: 906e89906d73328f7efcb261cbf8f4aa9ec3287d9a968a250b37cb0f1feee60286fb58b4873136b3210d47ef45c7e55a
ep_bytes: 68466fb9395f505968d8854000416800
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.pyme also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.c2e4b969b47a8acf
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.900994
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.9b47a8
BitDefenderThetaGen:NN.ZexaF.34182.puZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB422
AvastWin32:Evo-gen [Susp]
KasperskyTrojan.Win32.Copak.pyme
AlibabaTrojan:Win32/Copak.ac0137b6
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (CLOUD)
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB422
McAfee-GW-EditionBehavesLike.Win32.RAHack.dc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3517176
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!C2E4B969B47A
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
MAXmalware (ai score=87)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.pyme?

Trojan.Win32.Copak.pyme removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment