Trojan

Trojan.Win32.Copak.qyty removal tips

Malware Removal

The Trojan.Win32.Copak.qyty is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qyty virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qyty?


File Info:

name: 649F275DFB9EE186FDB2.mlw
path: /opt/CAPEv2/storage/binaries/0fdc70a2a40d154f9cea2612cb42867e36a9bb804f09d068f0f3dd86ba4ce207
crc32: EA8FB33D
md5: 649f275dfb9ee186fdb23ee563fba9fc
sha1: ab5562ca704186953234599eae80c2d44cc52682
sha256: 0fdc70a2a40d154f9cea2612cb42867e36a9bb804f09d068f0f3dd86ba4ce207
sha512: 9f74c8e1afd6ed13c30e33a9840e9ca2eb286243366a9ca8ceaa4e4fd790391242a9a7a6c661c6d19c4c2104b9ff158d114a6635e2c98f23650c077986d77fee
ssdeep: 1536:oTNSo5PDwaAF9PbWgapopUhuF5fTOl7ztUqdhMyl2B0wzw/G35GqtVOWouPjSp8F:4JDwhL+2q5z6qdOyQBzw4VOWp7SYx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11A93027A0E8F98DBFBC60C322FDD425A3DB9487F50231E87E754D489766928FC482152
sha3_384: 39dc008015e877fbba4e005381f1c1f116096ef4b5e248c0814245970e04580b3b342fda80aaa0a850c9c118e423c02d
ep_bytes: bb000000005221f929ff81ef01000000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qyty also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.649f275dfb9ee186
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Glupteba.a1f97a7b
K7GWTrojan ( 005435201 )
Cybereasonmalicious.a70418
BitDefenderThetaGen:NN.ZexaF.34742.fuY@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-9952474-0
KasperskyTrojan.Win32.Copak.qyty
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusTrojan.Win32.Copak.ivmwve
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
TACHYONTrojan/W32.Copak.94900.FK
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen17.59256
TrendMicroTROJ_GEN.R002C0DFR22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.nc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ceri
AviraTR/Dropper.Gen
ArcabitTrojan.Razy.DD3501
ViRobotTrojan.Win32.Z.Razy.94900.ARW
ZoneAlarmTrojan.Win32.Copak.qyty
MicrosoftTrojan:Win32/Glupteba.K!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R433805
Acronissuspicious
McAfeeGlupteba-FUBP!649F275DFB9E
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002C0DFR22
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qyty?

Trojan.Win32.Copak.qyty removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment