Trojan

What is “Trojan.Win32.Copak.kyhg”?

Malware Removal

The Trojan.Win32.Copak.kyhg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyhg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyhg?


File Info:

name: D42FE4AB46DA711674A2.mlw
path: /opt/CAPEv2/storage/binaries/bcdf7154a5ee78fa9342be2dfd3185622c494158bbf5fdf14da8dd87cfbda0cc
crc32: 141E8DBE
md5: d42fe4ab46da711674a2280ec12158ac
sha1: ef90ee4c2c702226918c765d00f2a1aaaa560426
sha256: bcdf7154a5ee78fa9342be2dfd3185622c494158bbf5fdf14da8dd87cfbda0cc
sha512: 8baf593f74129ac4de6c8b3abe1fd2cc788f5d5f5ab197be74e21ff7fa5d42e7c26e4ddbb1114cc6fb377ec07d8d27eb10457950470e6b54338e4d38e7536b30
ssdeep: 3072:++2DXdiBKyxJq3ZK1t2WVZuw0Ix+Z/ZGlUivGPWlDFqQbbSRtZgkYTe3:t2DXYZhz3+IxQBwfd/qWGRvTie3
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C8F3CFFFC96A44E4C3C189B0BDF540D2AA6A0A66F3DB445BE3D121145F8CB99E4B0937
sha3_384: caad6e12d0d10f5155afdaf6f7f204564bb0cca241c8a7ece15f3bd03d5ecd6418fd7c8353b6e026d739f96d65c89a7a
ep_bytes: b986b956a883ec04c70424d885400009
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyhg also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.d42fe4ab46da7116
ALYacGen:Variant.Razy.900994
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.b46da7
ArcabitTrojan.Razy.DDBF82
BitDefenderThetaGen:NN.ZexaF.34062.kuZ@aaoz!!o
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.kyhg
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!2132F03D4BCE
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazpwO8WkShhgikWgPdeUKOIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.kyhg?

Trojan.Win32.Copak.kyhg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment