Trojan

How to remove “Trojan.Win32.Copak.nixw”?

Malware Removal

The Trojan.Win32.Copak.nixw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nixw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.nixw?


File Info:

name: 198BF1AD65F0A8EEEAC2.mlw
path: /opt/CAPEv2/storage/binaries/7c6947b95ba2bf5c5b6f86fd802461593250eb9b53d5eec3174f5ea3cad8d6be
crc32: 45CD01E7
md5: 198bf1ad65f0a8eeeac2f91c4f737f47
sha1: 994ea20ee6e8a846cda22d32d3e27dad8ed814bd
sha256: 7c6947b95ba2bf5c5b6f86fd802461593250eb9b53d5eec3174f5ea3cad8d6be
sha512: 73fe082c243d5d0a9499c12d482d8fafb55e52b90bb8f380b202208ecf880f3930164611cb606f5274f7169a9109319b942d8a8b5d6cb65c769be59606def9bf
ssdeep: 3072:sHXt9Gke8Z7hFjfHwbPPaLBCk+ieapt8WhbUuQ7N+KUpYK:iXtskeibbHwTPaLnXomb6+KoL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T106F3DF1A497675F2E58A847D84B110975E2C393B20E6BF8F5C7F5F2D0304AE70D8A6B2
sha3_384: 01c5611e2e2cc6ab706912740e4b769652eef8babb0d0afe0e90a0c7ceb0562a4138e66d000ac3a824c51662f6eb246b
ep_bytes: 68984f44fe5909d301d268d885400021
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nixw also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.198bf1ad65f0a8ee
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.35389461
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAC22
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.nixw
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfda51
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAC22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
APEXMalicious
JiangminTrojan.Copak.bpyb
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.335CE85
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!198BF1AD65F0
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.d65f0a

How to remove Trojan.Win32.Copak.nixw?

Trojan.Win32.Copak.nixw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment