Trojan

How to remove “Trojan.Win32.Copak.llpa”?

Malware Removal

The Trojan.Win32.Copak.llpa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.llpa virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.llpa?


File Info:

name: CCBEF51771152F955302.mlw
path: /opt/CAPEv2/storage/binaries/00f7be01ecd8598e84edc6d8cfde199abf108258af7cfbe7d7e4e3dfe476cb13
crc32: 33BBA4EF
md5: ccbef51771152f95530232cd2600a9e5
sha1: 8d377544b39c44715fe793846a7074cd6ce1f622
sha256: 00f7be01ecd8598e84edc6d8cfde199abf108258af7cfbe7d7e4e3dfe476cb13
sha512: 9c4e6d3f1ad96d97326986c51ea82d62634f2e7f023e695acd1b822183f1c73b373ee4e5e73a0b899e6041b94327ee9a5c14814711c4dccdfd5129daa5a8b5ad
ssdeep: 3072:fLT5DgxxffGPwDU23PoJobY+EFd3AyRj5SjCmGHkBxQbPKQons6XRkll:fLdDgzBQ23vY+Eb3f5pmGH2ICQohXSr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T176F3CF48FEF3C870E6C61030E9A82C9D9BA7DBB3B27E1545443D14472DDA21867ADED2
sha3_384: c143987cd1dcf8887260f2397096cc4199524a19223d316496c9f9251ff0147be909fe3ef5555903301cb700ae0a7367
ep_bytes: 83ec04c7042477064cd35b68d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.llpa also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.ccbef51771152f95
McAfeeGenericRXGJ-XZ!B4E29FF3CD12
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.llpa
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfb277
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.865537 (B)
GDataGen:Variant.Razy.865537
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3378CA5
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazp3kfH5nwli8w5w633ppq4E)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.771152

How to remove Trojan.Win32.Copak.llpa?

Trojan.Win32.Copak.llpa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment