Trojan

Trojan.Win32.Copak.llar information

Malware Removal

The Trojan.Win32.Copak.llar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.llar virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.llar?


File Info:

name: EA7E9AB149A06E0CF07A.mlw
path: /opt/CAPEv2/storage/binaries/d8ed1301722c73ff4015cbfcc72b7ef4d7ad25b28b0d0d7447878aa9b28e65cc
crc32: 5FE1C57A
md5: ea7e9ab149a06e0cf07a0071d529a44f
sha1: 8411b5795baa4d51b16ccffaeaad4545365907d3
sha256: d8ed1301722c73ff4015cbfcc72b7ef4d7ad25b28b0d0d7447878aa9b28e65cc
sha512: 624843f06b52afeca17974bcc9a2f48aa6afe555f28897d582ca1b5bbda4153717d6150ded99c01ee0f22ff16c46048e36fb416e13bf8dc81cf412a8b1c14233
ssdeep: 3072:AvlHqDOcuoDFjh3txeJ2M5jsIZY1hiqKqxf35/V4syDpD4oTl8xlFlaZ4:uYOvAFRreJJjsIS6exR/CVVh8/my
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T116F3D024D57366C6D97AC0FFE964F8030DF86AC31796041AB3B772AF2508E643492DE9
sha3_384: 6f52c42ddaaa56d804b45d877211083195105eedcc13454c4de2cc33190f5cc87058463b9daac326bbf0057488064a8d
ep_bytes: 68a409dc235f4b680e58e7f85e68d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.llar also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.ea7e9ab149a06e0c
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Copak-9875194-0
KasperskyTrojan.Win32.Copak.llar
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce7b96
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.330F015
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!97125ABF1A6E
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazplUOQ+W36Hw2oC7qvbRGGC)
YandexTrojan.Copak!DQaPEXoumjI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.149a06
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.llar?

Trojan.Win32.Copak.llar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment