Trojan

Should I remove “Trojan.Win32.Copak.lrhj”?

Malware Removal

The Trojan.Win32.Copak.lrhj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lrhj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lrhj?


File Info:

name: 77215E4024610B352B32.mlw
path: /opt/CAPEv2/storage/binaries/918f8904d5ead7f0700207b7049fbf96641be04547cfe4393501efdbbfb6f8ee
crc32: C5D148FF
md5: 77215e4024610b352b328b715f8c9cce
sha1: 2ccd15cb9f780006caaf1ad37e76587701151893
sha256: 918f8904d5ead7f0700207b7049fbf96641be04547cfe4393501efdbbfb6f8ee
sha512: 62c2e29bb873d4c44224a16fbd00918ee670a8f6badefe0f4a48b3e7182ba26aa1325152006eb40ff03d9841eb179eee053ba5fdf15e3d3153f8c45007313b6b
ssdeep: 12288:F/WsvflGZ96Pknvu3x1qLVIHft7/zP96Pknvu3x1qL7:kGfQZQDTqLq/x/jQDTqL7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13505121D7499C2E2ED015CFE829BD0889DB34B5FE0ADD105E3A53884EB9252EC525FF2
sha3_384: bd0e9b6886dedc9f508e8df59c6cc80d20b6706136b49174bef40e2c1d7edf42fe6b26ddf6f560a40b301c244434f687
ep_bytes: bf188fb6cb29c168d885400068001040
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lrhj also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.77215e4024610b35
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.024610
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lrhj
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cfb0dc
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.870640
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33B2836
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!863FEC849DDF
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
RisingTrojan.Kryptik!1.BF57 (RDMK:cmRtazqiFeO7l6/4+Rz7du33DJz8)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.lrhj?

Trojan.Win32.Copak.lrhj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment