Trojan

Trojan.Win32.Copak.lrko (file analysis)

Malware Removal

The Trojan.Win32.Copak.lrko is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lrko virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lrko?


File Info:

name: 2DD128E2BFC6A6FAE487.mlw
path: /opt/CAPEv2/storage/binaries/4563bc10e5e0de7614822dd545ebca2ba98d73f265a843b2fb74ebd644c038a2
crc32: B78774A5
md5: 2dd128e2bfc6a6fae487d1cb6a1fe345
sha1: 3e571d628bddd81dea0d7e41796b9ca830a00df7
sha256: 4563bc10e5e0de7614822dd545ebca2ba98d73f265a843b2fb74ebd644c038a2
sha512: 265bdfa19b9604bf6ce5f316f0e571abdb483c214b363655a1270625a4ee1bd99dcab36a7fe3bb8ed55246886fd37a0c9a82a2859633f46a9ed1d85cd15f2d80
ssdeep: 12288:qF6LG7SZoJA+zDGwSSqj1QpLykRJUsL+G8NRIKn86GPhOxrfnEpWcqj1QpLykRJi:c66WIlKoE1kJ1mmPhwLcE1kJ1w
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10E0501DDC6B660DFFF677F32524986E03DF834862B95F126E112318DE428A84274A6CD
sha3_384: 19614652f31af1b441207abca55a6f8ff11edff90f40e512011970154e857bcde65575b2c3beeb2562d7995267efd99a
ep_bytes: 6898834a988b3c2483c40468d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lrko also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.2dd128e2bfc6a6fa
McAfeeGenericRXGJ-XZ!838CFE220611
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.2bfc6a
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyTrojan.Win32.Copak.lrko
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazrXIMMCjoHPS8cLRsym65hK)
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.bpag
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33AAD0F
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aOhSZ5
ALYacGen:Variant.Razy.870640
VBA32BScope.Trojan.Wacatac
TencentMalware.Win32.Gencirc.11e004c8
MAXmalware (ai score=89)
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lrko?

Trojan.Win32.Copak.lrko removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment