Trojan

Trojan.Win32.Copak.lqxk removal instruction

Malware Removal

The Trojan.Win32.Copak.lqxk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lqxk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lqxk?


File Info:

name: F0423C53F86EA870C698.mlw
path: /opt/CAPEv2/storage/binaries/eee0a0f01997977ee2d01139242c1edf3678748da4628e486c11f8ece9166867
crc32: CAE5AFFA
md5: f0423c53f86ea870c6985a5f7c919c68
sha1: 867f72863630e0cc4787186691abb52d2a5aff99
sha256: eee0a0f01997977ee2d01139242c1edf3678748da4628e486c11f8ece9166867
sha512: 91aa310ef26f40e2fc2e204dc9b7904580c2a7c1c6f2bb4201e16ebc22cf28242aa02a90d3cbaa0b1fbbca7761179596c95a8d67c37ce58710301e501917c21d
ssdeep: 3072:231RnCb9BRjZunsKU9o21jF2jouVj2tTjds8KytMnb+BsLVu3Gx:23PChXHKuo2X2t2tHi8KYWbcsLkI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T164F3DF558BE55F22C66C52B85064098A1F798C923FD373CE84F7327896BACEF3C08965
sha3_384: 934084eb3aabcfac92438622c9059d03f30c615891c7c8162b05b3fb8d91b96474b00e2457624aa1929e37c0697a3c98
ep_bytes: 681f46ec098b342483c40421db83ec04
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lqxk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.f0423c53f86ea870
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lqxk
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce86ff
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.334B808
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!A82063C870B3
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazpGF/tqkNr8bI8mDYhR2EDk)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.3f86ea
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.lqxk?

Trojan.Win32.Copak.lqxk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment