Trojan

Trojan.Win32.Copak.lgrd removal guide

Malware Removal

The Trojan.Win32.Copak.lgrd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lgrd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lgrd?


File Info:

name: 9A33524B45C455D2C9BF.mlw
path: /opt/CAPEv2/storage/binaries/cde76edf7628b526836494d2ed6c1d69748ca5e425f53fba302293aa037acfca
crc32: 200D294A
md5: 9a33524b45c455d2c9bf3c02107f8a32
sha1: 98d86b178c68d39742432cd6c2f0c1cecfc48117
sha256: cde76edf7628b526836494d2ed6c1d69748ca5e425f53fba302293aa037acfca
sha512: 8b24da38fdd1a70cec686443cce23496587423ed4dc1a7b3b4ed2572347bdf5534b0475fd5ac2cae7ce3b9e1263d91e0b8d6e438ecd6c3f15d95a728dd42a683
ssdeep: 3072:vpItQH/+ZDG9VBneqHGYWphViBGkon7vJFVF62OO62TombT:vG+HeDG9rn9HGhV/kqjJFa2tt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19AF3D0318D516E31E4CD9C72870371828BBE78B2EF53D81A8765E3BD804C567BBB1698
sha3_384: b9324673cb7f190d2f6b52a7e60921f420fc58971f9d174b25f6df294df30de5022bae66da2eac01ad17fc5bfe9bcdb3
ep_bytes: ba65c8a2c5565983ec04c70424d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lgrd also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.9a33524b45c455d2
McAfeeGenericRXGJ-XZ!AE27C5E1291D
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.b45c45
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lgrd
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bmgz
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.342A373
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
CylanceUnsafe
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazoY1COUoZQAddGIglD+Lcqd)
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lgrd?

Trojan.Win32.Copak.lgrd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment