Trojan

Trojan.Win32.Copak.liyx removal

Malware Removal

The Trojan.Win32.Copak.liyx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.liyx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.liyx?


File Info:

name: BFD6F173D3538EC00BED.mlw
path: /opt/CAPEv2/storage/binaries/a0eb18b3bb43088f6649ab3489f38f088817a5d2e462be5986675917e4ad3327
crc32: 9846743D
md5: bfd6f173d3538ec00bedf275e60b4990
sha1: 6e2318572f7472c017b219ba95a97e1c2d84c1a0
sha256: a0eb18b3bb43088f6649ab3489f38f088817a5d2e462be5986675917e4ad3327
sha512: 6e8a7341e9337d97fb97bbea6788f203c71fcbadfee815a7689434943f6689b43b13c0c8f56920afd2a40446090a575ecdd9fe704d169cbeb977769c27f1ba1e
ssdeep: 24576:BrNVD7e3QUIGg7e3QEl7e3QUIGg7e3Qu3ZPIx7e3QUIGg7e3QEl7e3QUIGg7e3Q9:B+BIGvRgBIGvvpPxBIGvRgBIGvC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D595BE4BCB9504F2ECFC163C3F427783DE8B16BA7B961DEA73583C8C57881A5518A4A4
sha3_384: a91bab837b9b1954c087841d27a812944fe67dba29c8b9d97369453ec637c98a313f34980eb7d2f538a27907786eea94
ep_bytes: 68217c73865a01d881eb0100000068d8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.liyx also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.bfd6f173d3538ec0
McAfeeGlupteba-FTSD!280710DF7189
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.900994
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9935141-0
KasperskyTrojan.Win32.Copak.liyx
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqklB2dYLz3rrU16k1HmBbv)
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.tc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.bnbw
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34D18A5
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.5vZ@aeSC5Sd
ALYacGen:Variant.Razy.900994
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
YandexTrojan.Copak!CIepLQcYNB8
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.3d3538
AvastWin32:Evo-gen [Susp]

How to remove Trojan.Win32.Copak.liyx?

Trojan.Win32.Copak.liyx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment