Trojan

Trojan.Win32.Copak.ljfb removal guide

Malware Removal

The Trojan.Win32.Copak.ljfb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ljfb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.ljfb?


File Info:

name: 56E7193A12E071F3DA4F.mlw
path: /opt/CAPEv2/storage/binaries/ac18b0a347e9cf4966524b0b31f48ae99b6070957049924e2e905ae35522dc4c
crc32: F0A85B12
md5: 56e7193a12e071f3da4f49fd489790c0
sha1: b8a890af97c0fa7a446761ee219c97babe69f266
sha256: ac18b0a347e9cf4966524b0b31f48ae99b6070957049924e2e905ae35522dc4c
sha512: 7ccd2b9792dc9c313a827e209e479e0ebc95eff875d805efef3dda336423a45cace42c8b37304ed0f7c062b2408df8e41111d89f06f91a7d9eac58e20561ada3
ssdeep: 6144:WA0Q7TtbJ6oByIbO9XVNAVqyzUBsRoriZ455C+/uUXVNAVqyzUBsRorP:WA/7ZbJ66yIa9lNgnYCyblNgns
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D864CE153CB6D7CFE21291321665E5484FBF2A8BB29992FDCA11F18E399CCCC4D45EA0
sha3_384: b6c7358a3a891f6cd89733693fb4b08a881d37d15a2bc1882b52dc2db8de620a2ba44b62bad6c406b3a237d420a5142f
ep_bytes: b9feb3629768d885400009d268001040
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ljfb also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
McAfeeGlupteba-FTSD!56E7193A12E0
CylanceUnsafe
K7AntiVirusTrojan ( 0058e60a1 )
K7GWTrojan ( 0058e60a1 )
Cybereasonmalicious.a12e07
ArcabitTrojan.Razy.DDBF82
BitDefenderThetaGen:NN.ZexaF.34638.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.ljfb
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
RisingTrojan.Generic@AI.100 (RDMK:cmRtazqK2l5KRM8PX7eWPyrmS164)
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
ZillyaTrojan.Injector.Win32.1405558
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.56e7193a12e071f3
EmsisoftGen:Variant.Razy.900994 (B)
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Copak.bnmk
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
APEXMalicious
TencentTrojan.Win32.Copak.wd
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.ljfb?

Trojan.Win32.Copak.ljfb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment