Trojan

What is “Trojan.Win32.Copak.lkhg”?

Malware Removal

The Trojan.Win32.Copak.lkhg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lkhg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lkhg?


File Info:

name: FF2459E4D6D65EF69D37.mlw
path: /opt/CAPEv2/storage/binaries/fbe1719cd1d3c568ed9b0dfb37002b26d4caf1449481ba95b272e70e86138957
crc32: 70DB6893
md5: ff2459e4d6d65ef69d37a38de395dca9
sha1: fa18e5aa2f2850847abb01d4a02c65676f6c41bc
sha256: fbe1719cd1d3c568ed9b0dfb37002b26d4caf1449481ba95b272e70e86138957
sha512: 34d11c0dd86bb82b3993f63f77af1d7f84d49cb89057e995449d9342c3f96ebbd267f3d33e00abbc73bf41fcf7aa2b312d93b139c68ae0bff12ecd1fc9810c3b
ssdeep: 3072:dxU25jo60ZxUBa8EtQRam+shou+OA5a5LBqAzIcNlCx/7V26i:dxUIo60ZOBPE6RLSucOqAzxNl85Fi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T141F3BE5B444A12A1DBC264B01ECC00C1E6A99A137FD61E47673E1FF8ED7E93CE868B54
sha3_384: f7e43e140b60eef240d51b6a406f54744018453bb729cb117055f4d001f0975c7efa2a76867107e3ba60c10bcc837487
ep_bytes: 6816a805a35a68d885400021fe680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lkhg also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
McAfeeGenericRXGJ-XZ!7D4FE997D697
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.900994
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4d6d65
CyrenW32/Zbot.W.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lkhg
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (CLASSIC)
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
FireEyeGeneric.mg.ff2459e4d6d65ef6
EmsisoftGen:Variant.Razy.900994 (B)
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333FA0A
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lkhg?

Trojan.Win32.Copak.lkhg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment