Trojan

How to remove “Trojan.Win32.Copak.kyrq”?

Malware Removal

The Trojan.Win32.Copak.kyrq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyrq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyrq?


File Info:

name: A9F8C6869CCDC05BBAA8.mlw
path: /opt/CAPEv2/storage/binaries/455e3fbed8d062a6cc7e62f5529e152228eee7bc2188a0bd05ba3ed9d52a45c0
crc32: E9D3A03C
md5: a9f8c6869ccdc05bbaa887136c7013ac
sha1: d2b2d004b7c2d0d0642b571385360a08a2a84ba7
sha256: 455e3fbed8d062a6cc7e62f5529e152228eee7bc2188a0bd05ba3ed9d52a45c0
sha512: dda501475deb6aec9ad04d067ab0c049853ddf96ff0360f674d8f597f143749e0d13121c6b40b831788a37bc26c3a8809d67fe16d1303f61f9350200c204db8f
ssdeep: 12288:D1LPKrmEaG72ZA21Ub9RJDQTCOYHK2AA0:DFPnG72ZA2qh7Ou0
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1769412CD50BC94C5E4DB5736328DA7E8A11E343B3CD140FAAA680CD67174CAB61BD8B9
sha3_384: dc14c18dea4ae4ad879ce72dcdd60ae0b6a297c92ad5dc97faaf19bccd93da76401b59ce4aa7d5b4f5aaf90b45ba1156
ep_bytes: b88da12d9681c1f0cad50668d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyrq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.a9f8c6869ccdc05b
McAfeeGenericRXGJ-XZ!433B9123A300
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.69ccdc
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.kyrq
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.11c92186
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.gc
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
eGambitUnsafe.AI_Score_98%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DD48F0
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34084.zuZ@aSwc1te
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Kryptik!1.D284 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.kyrq?

Trojan.Win32.Copak.kyrq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment