Trojan

Trojan.Win32.Copak.kyqp removal

Malware Removal

The Trojan.Win32.Copak.kyqp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyqp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyqp?


File Info:

name: D642C7B759465E0E8C31.mlw
path: /opt/CAPEv2/storage/binaries/bd07a0fd372b0a489dec19b2b8a3800df82f5d3919a87eb4866583027720792e
crc32: D587B520
md5: d642c7b759465e0e8c316ac81955474d
sha1: c76f7a022fad18a5a451125b8d5bf260b01a2fea
sha256: bd07a0fd372b0a489dec19b2b8a3800df82f5d3919a87eb4866583027720792e
sha512: 0a18561e8675871bf222fb8df513fcb0445161ffb6be89cd51babf18408251216c663a2f1fe2584e9192d0447a9cc37e2316fa7dc8f96b8fdd54668c8554a014
ssdeep: 1536:V8tB7frKI+M/U192N6dhO323ahdivKIJr+yZ0dN5H:VIBfKIr/04iwG3awFPZ0B
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14043018DEC429DEEE116C23F5B9988871D3503B8405DBF3D05E92896B447388F71A7E8
sha3_384: efd3bb85b904865d110a129c0d688a4f532dc62ee96409efe60a74bc54b0123d333e6bcaccc9b3b724e4cf6b9ea21c59
ep_bytes: bb0000000083ec04893c2409f04881c0
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyqp also known as:

LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.38228122
ALYacTrojan.GenericKD.38228122
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.74a7157d
K7GWTrojan ( 0057ffc71 )
K7AntiVirusTrojan ( 0057ffc71 )
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.kyqp
BitDefenderTrojan.GenericKD.38228122
NANO-AntivirusTrojan.Win32.Copak.ipiqif
MicroWorld-eScanTrojan.GenericKD.38228122
AvastWin32:Trojan-gen
TencentWin32.Trojan.Copak.Wqco
Ad-AwareTrojan.GenericKD.38228122
EmsisoftTrojan.GenericKD.38228122 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.PackedENT.214
TrendMicroTROJ_GEN.R002C0DL821
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
SophosMal/Generic-R + Troj/Agent-BGZJ
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38228122
JiangminTrojan.Generic.gyile
AviraHEUR/AGEN.1111440
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASBOL.C687
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D247509A
MicrosoftTrojan:Win32/Injector.RAQ!MTB
AhnLab-V3Malware/Win32.Generic.R369371
McAfeeGenericRXPH-TL!D642C7B75946
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0DL821
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Copak!/Za2+Y0dyqc
IkarusTrojan.Kryptik
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HITO!tr
BitDefenderThetaGen:NN.ZexaF.34084.dmW@aqxLbnk
AVGWin32:Trojan-gen
Cybereasonmalicious.22fad1
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.kyqp?

Trojan.Win32.Copak.kyqp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment