Trojan

Trojan.Win32.Copak.qypx removal tips

Malware Removal

The Trojan.Win32.Copak.qypx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qypx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qypx?


File Info:

name: C360EAC1E126EB6C41F6.mlw
path: /opt/CAPEv2/storage/binaries/fa86f1cc1e4add9d4da5525d01a58af2738c97d2039afd75972336475661330c
crc32: BE6269B0
md5: c360eac1e126eb6c41f61c23360eef99
sha1: 6314ddb688e8e7b88c912d4e9da79621c6dda350
sha256: fa86f1cc1e4add9d4da5525d01a58af2738c97d2039afd75972336475661330c
sha512: 6315da304a995f7b0e4e7caa9e643b4f3ac4b2a5b7a280dfbbbdffd177ad0a30f5763f2ff445b18a1fd97297412d947886c3cb2dbcb37ec6bfd4093c8db46d68
ssdeep: 1536:9UzArXTAx/7QRUnBRk8XXYP0Dm6YRYb3LqLawyOCU77zEQ0CeTx:ezl17QRUpXfDlYYB1O18QjIx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1269302AB031A200EE0A07978CE977FD720BE186B3175126EEB514D0BD6E5E0DA4D5BF1
sha3_384: 78e34f1bcbab2ac3f10bd57b6bca162233134d2298958986d65997cec80d05c7be60be28ff6fcc3bf62d56eb9d1b542e
ep_bytes: be0000000083ec04891c2489c95f81ea
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qypx also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.c360eac1e126eb6c
McAfeeGlupteba-FUBP!C360EAC1E126
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Copak.4158430e
K7GWTrojan ( 005435201 )
Cybereasonmalicious.688e8e
BitDefenderThetaGen:NN.ZexaF.34742.fuY@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
TrendMicro-HouseCallTROJ_GEN.R002C0PFS22
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-9952474-0
KasperskyTrojan.Win32.Copak.qypx
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
APEXMalicious
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
SophosMal/Generic-R + Troj/Agent-BGOS
DrWebTrojan.Siggen18.12539
TrendMicroTROJ_GEN.R002C0PFS22
McAfee-GW-EditionBehavesLike.Win32.RAHack.nc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.865537 (B)
IkarusWin32.Outbreak
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ceri
AviraTR/Dropper.Gen
ZoneAlarmTrojan.Win32.Copak.qypx
MicrosoftTrojan:Win32/Caynamer.MR!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R493456
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=87)
MalwarebytesTrojan.Dropper
AvastWin32:Trojan-gen
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Kryptik!+C9Sgf5jfEo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qypx?

Trojan.Win32.Copak.qypx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment