Trojan

Trojan.Win32.Copak.lcqk removal tips

Malware Removal

The Trojan.Win32.Copak.lcqk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lcqk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lcqk?


File Info:

name: D9B6DCE04D2B959AEC52.mlw
path: /opt/CAPEv2/storage/binaries/2c2d633ce1b26a1f3a90827010e290621436d8aedef9f35e4dfba85919b35ad0
crc32: BC3727C7
md5: d9b6dce04d2b959aec52d8d8efaa194c
sha1: a9986a47bf55e7ad26ac5a39652bbd63a1bfff5e
sha256: 2c2d633ce1b26a1f3a90827010e290621436d8aedef9f35e4dfba85919b35ad0
sha512: 3c36a398927f526712de7cfebf206053d54f92669afb012eaffb1568d170332db6384d015fd588d487c4d99b3f5e0a484cfd35ddacccf3709ee28a8af649440d
ssdeep: 3072:iTR8t2C0o8CB9xqG4koS/MnpouANLV4T2NVDmkrH8qz42sJF7WzwC:iTR8t2C060kMnpo1dV48HMFY
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DAF3CF845E874171FD1EB5FAD3BCA29887B7C4D6D28960CD8E7039CB7A6C4998588CF0
sha3_384: af3bdd89acd1f09eb4cbce483360cf6941c5cee2ccb277959e2aaddb7a005bc41f2b5e63a38c13825b2361e3738d61fd
ep_bytes: bac2d07b2068d885400021fbbb35185c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lcqk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.d9b6dce04d2b959a
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.04d2b9
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lcqk
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce6086
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.865537 (B)
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.bmem
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.330BA95
ArcabitTrojan.Razy.DD3501
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!4DB0AAA71045
MAXmalware (ai score=88)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lcqk?

Trojan.Win32.Copak.lcqk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment