Trojan

Trojan.Win32.Copak.kyga removal instruction

Malware Removal

The Trojan.Win32.Copak.kyga is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyga virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyga?


File Info:

name: E9475E7126F970936E53.mlw
path: /opt/CAPEv2/storage/binaries/a61d2e02ea3ecd9d7916e5f00fee1433a2cf23ec4e944a52cc4bcee5d7d1f07c
crc32: E70780F5
md5: e9475e7126f970936e53a3e3d6847a64
sha1: 00b102a32bf47fc5378e592f934bf3f302948a76
sha256: a61d2e02ea3ecd9d7916e5f00fee1433a2cf23ec4e944a52cc4bcee5d7d1f07c
sha512: d657195b1a9f5c691466cc94a4e123ac81a7288e678a2fe95aa213c4397b994aa73969d90b999ca7d9af8735d93f1a87bcf1e9a59cb8ad9a23794a1588a77883
ssdeep: 6144:hKT4jxBkbTcKNpLVowMLNyWVG9rGJboZmWU4oyMinHnBgBTZvww:h3MbTp7Ld7W4hikIW2yMZ7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D744126D979BE647DA8E4A33A235C04EBF1170DE0BFD43840C86AC8FD65B9D8C746252
sha3_384: 6d6e0f71b372d8cff1599cd4b19f378caeaad4de1df4f95f1ba0ac2f27370e0b93ea967aea576dda5eb83a5737558863
ep_bytes: 5589e5ba0000000089df414e89f84109
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyga also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.866955
FireEyeGeneric.mg.e9475e7126f97093
ALYacGen:Variant.Razy.866955
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057cf3b1 )
K7GWTrojan ( 0057cf3b1 )
Cybereasonmalicious.126f97
CyrenW32/Kryptik.DZR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.kyga
BitDefenderGen:Variant.Razy.866955
NANO-AntivirusTrojan.Win32.Copak.jhsyfj
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Razy.866955
EmsisoftGen:Variant.Razy.866955 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
ZillyaTrojan.Injector.Win32.1281073
TrendMicroTROJ_GEN.R03BC0DL921
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosMal/HckPk-A
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.866955
JiangminTrojan.Copak.bgxn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASCommon.1FB
ArcabitTrojan.Razy.DD3A8B
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2860595
McAfeeGenericRXQU-KR!E9475E7126F9
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R03BC0DL921
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Copak!2XFEwyvxKWk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34084.qmZ@aeBy@@e
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.kyga?

Trojan.Win32.Copak.kyga removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment