Trojan

Trojan.Win32.Copak.ljdf removal

Malware Removal

The Trojan.Win32.Copak.ljdf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ljdf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.ljdf?


File Info:

name: F27D4656692D045BBF44.mlw
path: /opt/CAPEv2/storage/binaries/19fea1b60c7f6950857090645f06ad141b5cd02286cea4ef509c5ec64d4f8d90
crc32: 2C9B32CB
md5: f27d4656692d045bbf44bd564abca13b
sha1: 44c618644bff52eab7b6027aca85acab3b5e9901
sha256: 19fea1b60c7f6950857090645f06ad141b5cd02286cea4ef509c5ec64d4f8d90
sha512: 736a9035d6a141fdfdfcf2bad6c187d877a1551384578b26a1317035fafba57da3c93cb19d76e2077ff946b29a8e218fe44a6e47c36dd1bf21f080045121a85c
ssdeep: 6144:brdytCL5PygWUwtQn4L8L8a2ktzxCL5Py4:brdytCxPKJ1a2ktzxCxt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15764E1BC99081A29D5F6B7704E8C1EE4942A5A72CF7DBDC58AC714C10BF25BB8178DE0
sha3_384: a61d9c2fcb0dc15c6dd7fa6eec3587d17d0b86b9355af81364a726100e3282bdb8c8e4f03a2d0a7af09ac61b036a6122
ep_bytes: be4a1d20bf68d885400083ec04c70424
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ljdf also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.f27d4656692d045b
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.6692d0
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.ljdf
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
EmsisoftGen:Variant.Razy.865537 (B)
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.bnpf
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGenericRXGJ-XZ!95231A912877
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqSgLJrRjLJRSClGqBKSujg)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.ljdf?

Trojan.Win32.Copak.ljdf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment