Trojan

Trojan.Win32.Copak.nirp information

Malware Removal

The Trojan.Win32.Copak.nirp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nirp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.nirp?


File Info:

name: EA467389D5DD607E42DF.mlw
path: /opt/CAPEv2/storage/binaries/602db3da04a2c65b73e24dea8229c5b85d510974ccf7aebaff0612236a00c874
crc32: 85A524DB
md5: ea467389d5dd607e42df5d64831ece0f
sha1: ed05036ae5932d7642d1985bb02fa9135ad10221
sha256: 602db3da04a2c65b73e24dea8229c5b85d510974ccf7aebaff0612236a00c874
sha512: 55fb1109d2ddb4e4a5ba9cb14e5fdf867d26f3f181dd2a83ddca0a72647c4e7ed24e71c340da797131fc7152c975791173dd65c81c761f6d53a2793b71cd25d1
ssdeep: 24576:F5SNipxyD2DBdK0wGCvcZ18/SjBdK0wGCvcw:F5aipx8mrYGBZ1eSjrYGBw
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C0501B0589797EAE6D81CB4B1EB3CEC70AF1C0679624F7B0A0A464547631DF066D8B3
sha3_384: 67066f764ba20a651f7a98cb7e6c2af256fb9c9487c5d3b92f66d3110b1b3ff09227b08f9bae8d097ed696c4734bc676
ep_bytes: bf2de793b629d281ee963475d368d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nirp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.ea467389d5dd607e
McAfeeGlupteba-FTSD!EA467389D5DD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.9d5dd6
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.nirp
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfae0a
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.870640
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33DF72D
MicrosoftTrojan:Win32/Glupteba.DB!MTB
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazpG0riRxOf4n3Rsxgl26BtX)
MAXmalware (ai score=84)
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.nirp?

Trojan.Win32.Copak.nirp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment