Worm

Worm:Win32/Copali!rfn removal

Malware Removal

The Worm:Win32/Copali!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Copali!rfn virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm:Win32/Copali!rfn?


File Info:

name: 2ECCF428853FD26C83B9.mlw
path: /opt/CAPEv2/storage/binaries/036a738dd6241f6ad7769709a60571f557879aabdb731ffdf6066af4db7edf28
crc32: B3471F45
md5: 2eccf428853fd26c83b9657a39c6d588
sha1: da09b8ffa8679e9bff87c6e0fa2af6e87d0e3b91
sha256: 036a738dd6241f6ad7769709a60571f557879aabdb731ffdf6066af4db7edf28
sha512: 5e955aa7330625bdcc6706ddbf3077a7218794602c33f235016ed718e4b90b1402b7492dc7fd7b3c1bbd06fdbca0666ea6b3eb77377d5c75d17c7e8fbf4ef443
ssdeep: 3072:9sa4mQQo+07AzQY4sFHxB5+eJ9NGqXgvs4stYIDQN4Ar/FzKs:9tQ5Y4sFHxB5+eDNGXU4sFg52s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15604E51BF121F098E5924178306DEA8AF5587E7315546D32FB90BB2839B53AFA0F5B03
sha3_384: a176671b24f046d83af38bbd2509052ee82a598efdbf344793e395e7c5c1bf0e198265c0f99cd60074e46d2fd7f97841
ep_bytes: 6868784000e8f0ffffff000000000000
timestamp: 2014-03-20 10:41:32

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: DOCUMENT
OriginalFilename: DOCUMENT.exe

Worm:Win32/Copali!rfn also known as:

LionicTrojan.Win32.Agentb.tnql
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.91502
FireEyeGeneric.mg.2eccf428853fd26c
McAfeeGenericRXDU-RW!2ECCF428853F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusP2PWorm ( 00486ea71 )
AlibabaTrojan:Win32/Beebone.ea48ca9f
K7GWP2PWorm ( 00486ea71 )
Cybereasonmalicious.8853fd
BitDefenderThetaGen:NN.ZevbaF.34294.lm0@aKRyXyai
CyrenW32/S-a42f8a3c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.MFPBQAK
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
Paloaltogeneric.ml
ClamAVWin.Dropper.Cerber-7134131-0
KasperskyTrojan.Win32.Agentb.btmh
BitDefenderGen:Variant.Cerbu.91502
NANO-AntivirusTrojan.Win32.TrjGen.deyzgg
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:Agent-AXUS [Trj]
TencentWin32.Trojan.Agentb.Hvts
Ad-AwareGen:Variant.Cerbu.91502
SophosML/PE-A
ComodoTrojWare.Win32.Swisyn.DFX@5ci87q
DrWebTrojan.Siggen6.19362
ZillyaTrojan.Agentb.Win32.18750
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Cerbu.91502 (B)
APEXMalicious
GDataGen:Variant.Cerbu.91502
JiangminTrojan/Swisyn.wsw
eGambitUnsafe.AI_Score_99%
AviraTR/Beebone.rhwnabs
Antiy-AVLTrojan/Generic.ASMalwS.93BFFC
GridinsoftRansom.Win32.Zbot.sa
MicrosoftWorm:Win32/Copali!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R106377
VBA32Trojan.Agentb
ALYacGen:Variant.Cerbu.91502
MAXmalware (ai score=100)
MalwarebytesWorm.Agent
YandexTrojan.GenAsa!UB1ZEjQvu58
IkarusTrojan.Win32.Agentb
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agentb.BTMH!tr
WebrootTrojan.Comroki.Gen
AVGWin32:Agent-AXUS [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Copali!rfn?

Worm:Win32/Copali!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment