Trojan

How to remove “Trojan.Win32.Copak.lfij”?

Malware Removal

The Trojan.Win32.Copak.lfij is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lfij virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lfij?


File Info:

name: 21A22CE0FAE9C061FA9A.mlw
path: /opt/CAPEv2/storage/binaries/0a5842e16b0ed0bf0cb102d80373b46d473b1f5f9a9dff2f6a49e41cac1bdbeb
crc32: 66E6F4DC
md5: 21a22ce0fae9c061fa9adc51beda3699
sha1: a982c5ceccdcba5fed82b656490a430171a55e1d
sha256: 0a5842e16b0ed0bf0cb102d80373b46d473b1f5f9a9dff2f6a49e41cac1bdbeb
sha512: a3655722754c73c80a7e72fb0fd7d9ce49cebfc91a57d73fb2552c227888d2f2be1bd02b667d5289b7c5cba5d3c5e2b6d15ea8b7caa28efc5f7b5a8b18c80684
ssdeep: 24576:bHeg78ZJ4AUH8ZJ4MIOH58ZJ4AUH8ZJ49:beg78ZJ4AUH8ZJ4C8ZJ4AUH8ZJ49
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10E15CFC471A3A810D2E84B38C23D769DB7A74AB1FCC2F3D9CE6D679A88582444945CFD
sha3_384: cab8b2380ccea846eaee63fae2c37faf1cdc81618cdd28965389c235ba1771da1446a0638528a3798c8275b92c0fe545
ep_bytes: 681ab828f15868d885400001f1680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lfij also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.21a22ce0fae9c061
McAfeeGenericRXGJ-XY!D6F79B4FFC1C
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1339640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.0fae9c
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Iho3wxi-9909811-0
KasperskyTrojan.Win32.Copak.lfij
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazoEn3Lla1rSbdgjJlmvT263)
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333D115
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.3uZ@aeSC5Sd
ALYacGen:Variant.Razy.865537
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
YandexTrojan.Copak!TGdaQCibwyI
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lfij?

Trojan.Win32.Copak.lfij removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment