Trojan

Trojan.Win32.Copak.kynb removal guide

Malware Removal

The Trojan.Win32.Copak.kynb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kynb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.kynb?


File Info:

name: F0221EC550BB9687D559.mlw
path: /opt/CAPEv2/storage/binaries/a424457a12233223b5b1244e8e2055633c820c5e8ba0820c67412cfdd417e34f
crc32: 2881C754
md5: f0221ec550bb9687d55982dff03acae8
sha1: fd72f7f51c411a42cd16f1b206ea82a80bd53756
sha256: a424457a12233223b5b1244e8e2055633c820c5e8ba0820c67412cfdd417e34f
sha512: 6549abe398dd00926ddf91c8c3b1f608026c4c7f0808c1b4687c69456e12a3993908c827525c6fb09bedd2eb9c134a0293bcc4a85a46bca6f1334f5f67a3b8e9
ssdeep: 49152:IrJBA1+GPUHvC/mxtv+zZIYUukElXEygt5sKXujJDN2rrfWKWWe7fS4hEKkBb:I3AkGcHtrvMIHEo7sXaHWz7L4B
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11DB533718CB1F590F924CAF5AE2EA3C27E17EB44F94982F7A7EA427C252D1611340D1B
sha3_384: a0041b477864a62bc6305d3363844553d0516991800cb9fd70f433f3505c1459baf839872cf99ead64632d2e71213c9e
ep_bytes: 6800000000595001fb535b5a21ff524b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kynb also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.51c411
BitDefenderThetaGen:NN.ZexaF.34062.toZ@aGaFGsl
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyTrojan.Win32.Copak.kynb
TencentTrojan.Win32.Coinminer.yi
SophosMal/Generic-R
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPREPacker.NSAnti.Gen (v)
TrendMicroTROJ_GEN.R002C0DL721
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Paloaltogeneric.ml
GDataWin32.Application.Coinminer.692VW7
JiangminTrojan.Copak.bdy
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C689
GridinsoftRansom.Win32.Gen.sa
ViRobotTrojan.Win32.Z.Injector.2409984.AFO
MicrosoftTrojan:Win32/Injector.RAQ!MTB
McAfeeGenericRXAA-FA!F0221EC550BB
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DL721
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Injector!gGlPyMZWKK0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.kynb?

Trojan.Win32.Copak.kynb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment