Trojan

Should I remove “Trojan.Win32.Copak.tuls”?

Malware Removal

The Trojan.Win32.Copak.tuls is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.tuls virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.tuls?


File Info:

name: 96B9E94BF598B283C4CA.mlw
path: /opt/CAPEv2/storage/binaries/d410c8622a46c5783655b0b8fedd4a67ed4dd7cda209340ae3089026643f99b7
crc32: 46CD4A7C
md5: 96b9e94bf598b283c4ca61c055d748cb
sha1: 1e583a2ff3f634e9e07b1375125332a5f255cf92
sha256: d410c8622a46c5783655b0b8fedd4a67ed4dd7cda209340ae3089026643f99b7
sha512: 8f96dfec41a13f2166dd6213e67c65c84c4e83179d6503f847724abc7627d3cee00c7ba3021114d6ee72bef6be8119c7763da091a7310d35a78a1682acd6e7fe
ssdeep: 24576:6FLR8pzUJXOqO4mzJvD9Prda/ZSTeF+77LX:6F8QJ+qnmVpPrdgqeF+bX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17D25BF68120D55AFD0DB8779EE6DDEF111BA69786E63D2B132C1BCE738223C0A5112F1
sha3_384: d0e6c8629407a0054a28740fd62d8bea7a385c87204b68808bdbae715f0721237425ac6114c17c7649ccc444f93d7722
ep_bytes: 280d05fe786481797d8588e8ffcfe052
timestamp: 1975-06-24 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.tuls also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.317678
ClamAVWin.Packed.Razy-9836307-0
FireEyeGeneric.mg.96b9e94bf598b283
McAfeePacked-FJB!96B9E94BF598
Cylanceunsafe
ZillyaTrojan.Generic.Win32.717858
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.990b1129
K7GWTrojan ( 005a45ef1 )
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderThetaGen:NN.ZexaF.36318.88Z@aSJ4gId
CyrenW32/Copak.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.tuls
BitDefenderGen:Variant.Lazy.317678
NANO-AntivirusTrojan.Win32.Kryptik.flbujn
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Kryptik.hohhe
DrWebTrojan.PackedENT.183
VIPREGen:Variant.Lazy.317678
TrendMicroTROJ_GEN.R002C0DDC23
McAfee-GW-EditionBehavesLike.Win32.Fujacks.dc
EmsisoftGen:Variant.Lazy.317678 (B)
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.11YPVZ
JiangminTrojan.Generic.cvlgq
AviraTR/Kryptik.hohhe
Antiy-AVLTrojan/Win32.Kryptik.GIFY
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D4D8EE
ZoneAlarmTrojan.Win32.Copak.tuls
MicrosoftTrojan:Win32/Glupteba.MT!MTB
GoogleDetected
AhnLab-V3Packed/Win.Generic.R565453
VBA32Trojan.Copak
ALYacGen:Variant.Lazy.317678
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DDC23
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Copak.tuls?

Trojan.Win32.Copak.tuls removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment