Trojan

About “Trojan.Win32.Copak.llub” infection

Malware Removal

The Trojan.Win32.Copak.llub is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.llub virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.llub?


File Info:

name: DD116A3556DA9792FD0F.mlw
path: /opt/CAPEv2/storage/binaries/2b46ab21fbc8ef466db54306b4f43ead5ea353ab2813b9e7593ad941e34e6d1d
crc32: 710165A4
md5: dd116a3556da9792fd0f7706a0787e58
sha1: fdabd2bb85579e0b06e7554994be47237c2e44ff
sha256: 2b46ab21fbc8ef466db54306b4f43ead5ea353ab2813b9e7593ad941e34e6d1d
sha512: 8c014b88cbd245bba233db5b8b6ed092104c0030ab11c684b06534b541b90567d89a49958e26b0f0728e7d4724f17437ba646628fb6147ac1dd6e8cd67809b6c
ssdeep: 24576:5hxXKbBdhYbIbdKpf7K8ZbGvT1kYbIbdKpfi:Fabtxqxp
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17C05011B66424C96EE48A87786BF2670584A9CC6F87D312EADD34F3F3996334913631C
sha3_384: cdc4f561d331a74a341d36b8585a116f1ea3663032f7e2b95004c1bb08e86d43962d189849159918b3563e54fe36e4d6
ep_bytes: ba4bc5c33a68d8854000680010400021
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.llub also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.dd116a3556da9792
ALYacGen:Variant.Razy.870640
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.b06dac15
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.556da9
BitDefenderThetaGen:NN.ZexaF.34160.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
Paloaltogeneric.ml
ClamAVWin.Packed.Ilmwieh-9883889-0
KasperskyTrojan.Win32.Copak.llub
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cfbce4
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
ZillyaTrojan.Injector.Win32.1343723
TrendMicroTROJ_GEN.R002C0DA622
SophosMal/Generic-R + Troj/Agent-BGOS
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.boma
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3344DC6
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD48F0
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=87)
APEXMalicious
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqQcV7qw/YRkKk7YO19pgoj)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.llub?

Trojan.Win32.Copak.llub removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment