Trojan

What is “Trojan.Win32.Copak.lgcj”?

Malware Removal

The Trojan.Win32.Copak.lgcj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lgcj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.lgcj?


File Info:

name: 0EAE1E293F74C293D086.mlw
path: /opt/CAPEv2/storage/binaries/77992c986e1319840d0088217d7f9335af0de28b6640a3f287b407f4199ea185
crc32: 7C1E6170
md5: 0eae1e293f74c293d0868c2b50d1ab8a
sha1: 6cec4bc33e3d9b2cf6d0e474448b87fa6f77c369
sha256: 77992c986e1319840d0088217d7f9335af0de28b6640a3f287b407f4199ea185
sha512: a59228577558bea1c6a630e6bb891b7b5893f394ae8f63bd0ac7a56dd4e5546a2ff5ef59190201e0e5a5e7980d57c083bae9f932cfa801a029089ce823643232
ssdeep: 49152:sKmhZIsve4sQlIsFABCZQlIVQlIsFABCZQlIS:MTm4s898I898n
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BC75028E583B1495F0E3A87C1749648180CE44F6122E67FFCD2CF4CCE8DE7A5A645EA9
sha3_384: b09b1c77a68be58809a4196ebc52d40898f0f109bd7644dd960368c844234a8bf6da22f9a942a4f71aa09884d1f9742f
ep_bytes: bb28fdeefa09c281c0a9d3d88668d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lgcj also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.0eae1e293f74c293
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.93f74c
BitDefenderThetaGen:NN.ZexaF.34114.KvZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lgcj
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrLbLKqzooL9p7/oZ53VYrm)
Ad-AwareGen:Variant.Razy.870640
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.tc
EmsisoftGen:Variant.Razy.870640 (B)
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.blvi
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3500A5C
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!0EAE1E293F74
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.lgcj?

Trojan.Win32.Copak.lgcj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment