Trojan

Trojan.Win32.Copak.nsqk removal guide

Malware Removal

The Trojan.Win32.Copak.nsqk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nsqk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.nsqk?


File Info:

name: 2176A822CA20E1FE2C1B.mlw
path: /opt/CAPEv2/storage/binaries/05ff0637fdc347a0e5b4a39400767eed26aab04c3104c38eddcaa829ecac3a9d
crc32: E8FF3155
md5: 2176a822ca20e1fe2c1b442ae31aff9c
sha1: 66378109e74e54fe5c830b444f366bdb4215f213
sha256: 05ff0637fdc347a0e5b4a39400767eed26aab04c3104c38eddcaa829ecac3a9d
sha512: 8c0f28fc9228f32fa25cc5f3c500fa8c6d39fdde80d44c764b9b9c26be4776911b8a39df163dde2ce40b43da834e9b0b56cec81530367cfeb9eb0df29bce46d8
ssdeep: 196608:6b2JdKJ2lz2JdKJ2U2JdKJ2lz2JdKJ2G2JdKJ2lz2JdKJ2U2JdKJ2lz2JdKJ2r:6OdKU2dKqdKU2dKcdKU2dKqdKU2dKQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T173661268DEC17B7FF983F77442A7BC9C456EA4C3B082296CBF66458240776A4D663803
sha3_384: 1eadaabbea208e8c216fcc677c46f27711ac20d60c270b3cb20825611dda959eec705fdebf4e3ff6fb7989ef0777d88c
ep_bytes: bb0c16517c4868d885400029c7680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nsqk also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2176a822ca20e1fe
McAfeeGlupteba-FTSD!2176A822CA20
MalwarebytesTrojan.Injector
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Trojan.Heur2.@xZ@ITwc1te
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.nsqk
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur2.@xZ@ITwc1te
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazptTUc37PEmOATLXChzEuct)
Ad-AwareGen:Trojan.Heur2.@xZ@ITwc1te
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.vc
EmsisoftGen:Trojan.Heur2.@xZ@ITwc1te (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Trojan.Heur2.@xZ@ITwc1te
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
BitDefenderThetaAI:Packer.BE4C61461C
ALYacGen:Trojan.Heur2.@xZ@ITwc1te
VBA32BScope.Trojan.Wacatac
TencentTrojan.Win32.Copak.wc
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.2ca20e
AvastWin32:Trojan-gen

How to remove Trojan.Win32.Copak.nsqk?

Trojan.Win32.Copak.nsqk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment