Trojan

Trojan.Win32.Copak.kyid removal

Malware Removal

The Trojan.Win32.Copak.kyid is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyid virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyid?


File Info:

name: 489907A8139C39CA2D8F.mlw
path: /opt/CAPEv2/storage/binaries/3f99e9455f5c7e1e8ab2ac28fd79eb38a5ec76729992a68f426a8de06427e58b
crc32: F7219EE6
md5: 489907a8139c39ca2d8f1f98e3414597
sha1: 8b9adcbec1065d7ca0316ca9e25ff9e485e85909
sha256: 3f99e9455f5c7e1e8ab2ac28fd79eb38a5ec76729992a68f426a8de06427e58b
sha512: 69ba32256ada22b9d0fbcfe34f1e993df06f3e73fe0c73ac5f5b708546393ca81a2d220ae3fafb60ea4d22949507ba7e204e721e80fb82354bb0064a8544d03a
ssdeep: 1536:zLwTgeMqn1tNlWoYwSfYw4AEZeA458fPqZR6rc5AEhSGJ:zLGg+WoYwSfbEj4583qerHEhSC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FC83D0DC2A137C64E2828A370C7B4DDCF3BFDF59E272711596E5272C1A952FD8AA0048
sha3_384: c82a141eeb84402c644e1459cb31d3c10b6d4f32b5fc151242f099559f2d8620e47b96a15e4730f7467c1c82ebe337b1
ep_bytes: bbf34a87b983ec04c70424d885400081
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyid also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Trojan.Heur.fuX@Iboz!!o
FireEyeGeneric.mg.489907a8139c39ca
ALYacGen:Trojan.Heur.fuX@Iboz!!o
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaAI:Packer.AC698B831B
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.kyid
BitDefenderGen:Trojan.Heur.fuX@Iboz!!o
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastFileRepMalware
Ad-AwareGen:Trojan.Heur.fuX@Iboz!!o
EmsisoftGen:Trojan.Heur.fuX@Iboz!!o (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Crypt
JiangminTrojan.Copak.bgpq
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34E535C
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Trojan.Heur.fuX@Iboz!!o
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!489907A8139C
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazorr/K31zayGVB5XAiNvuaS)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGFileRepMalware
Cybereasonmalicious.8139c3

How to remove Trojan.Win32.Copak.kyid?

Trojan.Win32.Copak.kyid removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment