Trojan

About “Trojan.Win32.Copak.lhhq” infection

Malware Removal

The Trojan.Win32.Copak.lhhq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lhhq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lhhq?


File Info:

name: 6AEF7043A6F7024B05FB.mlw
path: /opt/CAPEv2/storage/binaries/f07c9338300475d3d1f94a674f9dc89027d1626977e0a845df32109b97e6eaa2
crc32: 009207E6
md5: 6aef7043a6f7024b05fb815dbd8bbf69
sha1: 74f9edb0f4cb43f0cfb0f427dbee0ff8a6705c6f
sha256: f07c9338300475d3d1f94a674f9dc89027d1626977e0a845df32109b97e6eaa2
sha512: 77740c7e55c6ceb1c3bcedf0f6516eb402e6273120a158082e1b640afbcb63577eaa611dc320b35aa9ac4c8d18a299b0a6817febeff566a00a84b16f5e7749da
ssdeep: 24576:n7PTSnLo1cFNNyMx5W3+jAY4eF5U1cFNN0:n7PTSLo1cO+jr35U1ce
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1810512C88A665E3FC819B474901704E7DA2E019FFAB039644B08616B51873FCB57BF76
sha3_384: 48f5f783f7946e2911a4edf5f792543b658627eb53f51f7ac9aca302c8ca356bc4a2cdd59ed71e1ab974bf0ff993cd2d
ep_bytes: 83ec04c7042497fb5bba5909c081c2ef
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lhhq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.6aef7043a6f7024b
McAfeeGenericRXGJ-XZ!E71BF0464CEA
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.3a6f70
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.lhhq
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cfb175
Ad-AwareGen:Variant.Razy.870640
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.870640 (B)
GDataGen:Variant.Razy.870640
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3351C63
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
MAXmalware (ai score=86)
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazqjnNShJjv8LzufDwsRTyDQ)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lhhq?

Trojan.Win32.Copak.lhhq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment