Trojan

How to remove “Trojan.Win32.Copak.llfa”?

Malware Removal

The Trojan.Win32.Copak.llfa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.llfa virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.llfa?


File Info:

name: 2A4F298B1C8F2315D392.mlw
path: /opt/CAPEv2/storage/binaries/e7edcd48921f8edca6762a28b7810ec3a16575a4d310d784990e46d4387287a5
crc32: 47D4E9C9
md5: 2a4f298b1c8f2315d3927f6b1f857c46
sha1: 53906ba09a05ed6a7bbb3ffd5930dfc48a2dee24
sha256: e7edcd48921f8edca6762a28b7810ec3a16575a4d310d784990e46d4387287a5
sha512: fc3a814217817861afd8e59b5ba3bfebe52ac3304c4d99ac1ad498870769ba5e3ba4fe797b05e562161e96ebb241681c6fbd576adf6d1a8bf22eee8e2cd7b3b6
ssdeep: 12288:pvP74Du+sfQGWVcDZR4tvDyTL8XacMn4186TDCcAl5jOYhtvDyTL8XaS:Z74Du+kQ1CNR4tWIFM418zhZhtWIR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16F0501A57CB6E10AE3E644300BAFD9642869F1370E50B2D93F9E5DE53CD487C2E15EA0
sha3_384: 2292a245ac7839c5e6f9a486bf9996d42bda99ebcb4371b4b2524830bd7109f7e0fd5fedc1ed18e5d7b47db4df16b3ad
ep_bytes: b92dee58ff68d885400081e8f122970b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.llfa also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.2a4f298b1c8f2315
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.577f0034
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.b1c8f2
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Copak.llfa
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cfd9a1
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAA22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
JiangminTrojan.Copak.bolz
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34FDB2E
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD48F0
ViRobotTrojan.Win32.Z.Razy.821249.JDY
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!2A4F298B1C8F
MAXmalware (ai score=88)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DAA22
RisingTrojan.Injector!1.CD26 (CLASSIC)
YandexTrojan.Copak!93n6zWw6VXA
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.llfa?

Trojan.Win32.Copak.llfa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment