Trojan

About “Trojan.Win32.Copak.kpec” infection

Malware Removal

The Trojan.Win32.Copak.kpec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kpec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.kpec?


File Info:

name: EDC8A59491D769E18D58.mlw
path: /opt/CAPEv2/storage/binaries/06c87f6d106025673a2c634056bf72da641879045b0edd95032411146d9e05b7
crc32: 3B2A4E49
md5: edc8a59491d769e18d58f8fb831f6cb1
sha1: 50b50863e68a7cb34499a6281b6867ef3ff45e63
sha256: 06c87f6d106025673a2c634056bf72da641879045b0edd95032411146d9e05b7
sha512: 0dc4b82b2483bd4b860dbbae448599097a4ebca1311c088c4023637b7a59abbdb61a6aaa109f3fa2a62be6d7f5359de78553b629bbfea81ab3f289ad98ad50fb
ssdeep: 49152:ebF7L/RZSeKxAEZqPxhO9MZHPzWwDH/X:UFvRZhKFsP79xKwz/X
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D875335D9BE71143F622293E32A177887E36CBFDACA64A3A5A39473C2F152358DD4430
sha3_384: 780ddaa7909da4181f7879212b9411e152c6f1925ba81bdca682e3d5e4ad6b14aafce56515732852cdc67b0870e11d46
ep_bytes: b9000000005781ee51b001db4e01f05a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kpec also known as:

LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.327786
FireEyeGeneric.mg.edc8a59491d769e1
ALYacGen:Variant.Lazy.327786
MalwarebytesMalware.Heuristic.1003
VIPREGen:Variant.Lazy.327786
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.3e68a7
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
KasperskyTrojan.Win32.Copak.kpec
BitDefenderGen:Variant.Lazy.327786
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
EmsisoftGen:Variant.Lazy.327786 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/TibsPak
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Lazy.327786
GoogleDetected
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Lazy.D5006A
ZoneAlarmTrojan.Win32.Copak.kpec
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Win32/Viking.suspicious
Acronissuspicious
McAfeeGenericRXAA-FA!EDC8A59491D7
VBA32Trojan.Packed
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.C865 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.36196.InZ@aekCYye
AVGWin32:CoinminerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.kpec?

Trojan.Win32.Copak.kpec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment