Trojan

UDS:Trojan.Win32.Copak.bmphe malicious file

Malware Removal

The UDS:Trojan.Win32.Copak.bmphe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Copak.bmphe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:Trojan.Win32.Copak.bmphe?


File Info:

name: 2A39AF1072A168E22CB5.mlw
path: /opt/CAPEv2/storage/binaries/9212ee326e3a14ff9749f254aa1becb79305f464c2b1defaf30a7cf99564d3eb
crc32: BBFB46C1
md5: 2a39af1072a168e22cb569b83200d604
sha1: 67622962936ccfe3f119ad2ebada4f0ec380b274
sha256: 9212ee326e3a14ff9749f254aa1becb79305f464c2b1defaf30a7cf99564d3eb
sha512: d71618075c516fc875deeb81e93caa1e52fe81f143e7aea26b12f0b53da8210d196e9e03a92dab3e4ea4d0ad910fd6d0e502a464c6c0f27502eed1b5ea51e1f3
ssdeep: 3072:ZDV61z/1oPxmOvCVLPirNBsXSeTdodNNhXCAb3Fz8yDO6etOczVvzbQznje7mhdF:ZDGdVO6FeleTdozNhtVQY+trbc67dAN5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D444CFBEF3531BADCAE673BB130E6CC39644B31D0236A3D87F4016CA95E614596F2258
sha3_384: 776b9fec85431f20ab41bbab72b3f71431d267d5a1766e76f00c0c46459890e6f67c2d21d482e5d9149cafc2b61f5b19
ep_bytes: 48ce18b518a79c321d4695a30f04fd19
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

UDS:Trojan.Win32.Copak.bmphe also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2a39af1072a168e2
SkyhighBehavesLike.Win32.Backdoor.dc
McAfeeTrojan-FVOQ!2A39AF1072A1
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.2936cc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
ClamAVWin.Malware.Generic-10019342-0
KasperskyUDS:Trojan.Win32.Copak.bmphe
NANO-AntivirusTrojan.Win32.Injuke.imhocm
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kq
TACHYONTrojan/W32.Selfmod
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.123
SophosMal/Inject-GJ
IkarusTrojan-Downloader.Win32.FakeAlert
GDataWin32.Trojan.PSE.11XGYE9
JiangminTrojan.Generic.gcqwx
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.986
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ZoneAlarmUDS:Trojan.Win32.Copak.bmphe
MicrosoftTrojan:Win32/Glupteba.MT!MTB
VaristW32/Trojan.NJGF-3047
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.q4Z@aiNtz3j
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove UDS:Trojan.Win32.Copak.bmphe?

UDS:Trojan.Win32.Copak.bmphe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment