Home Malware Programs Browser Hijackers Coppingo.com

Coppingo.com

Posted: May 14, 2015

Threat Metric

Ranking: 1,282
Threat Level: 5/10
Infected PCs: 120,695
First Seen: May 14, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Get_coppingo\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 478.72 KB (478720 bytes)
MD5: 655aaeeb70da0f3df44f116c868c607d
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Get_coppingo\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Coppingo\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 466.43 KB (466432 bytes)
MD5: 80d10df7727fb6ad28003e16a1f2b605
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Coppingo\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Get_coppingo\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 463.36 KB (463360 bytes)
MD5: 13e8226c81af8b88dd9cbb23f17ce593
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Get_coppingo\UpdateProc
Group: Malware file
Last Updated: March 23, 2016

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Get_coppingo.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Get_coppingo.job.fpSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\GET_CoppingoSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\GET_Coppingo

Additional Information

The following directories were created:
%APPDATA%\Get_coppingo%PROGRAMFILES(x86)%\GET_Coppingo
The following URL's were detected:
coppingo.com
Loading...