Trojan

Trojan.Win32.Copak.lahy removal tips

Malware Removal

The Trojan.Win32.Copak.lahy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lahy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.lahy?


File Info:

name: 12C91270057E06359B12.mlw
path: /opt/CAPEv2/storage/binaries/eafcd1deb8fd39977e42fa9b4be386f54a06cc81f783474f171f5ee554799769
crc32: 2F30942F
md5: 12c91270057e06359b128908dd718521
sha1: e9ed6a2df432c3385a8c203398d6baed4b3d6d6a
sha256: eafcd1deb8fd39977e42fa9b4be386f54a06cc81f783474f171f5ee554799769
sha512: 7a24c67eeba97acff7e978401fbe82440905876ac4d15bac00b7891a01be3864e2f707f08143a5b0726d86a449ed0e47234cbd7ebc827b802f14c2fc5771ffa7
ssdeep: 12288:B00S+VPBr28cj3+YMEZs4paYHbm2J3JAEwej3+YMEZs4paZ:HS8pi86+LEZs4UYqb6+LEZs4UZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1ED0512383576C5BEDE3826F42791E47A40ACC8D26E71B50B0F52D74B78F68B5E08B429
sha3_384: 0992c357488312d1f1cccb53547d15d3a71fc710435f4832ab7d8b2c57598c51aa8f74be3e25a4d3debc05d3d952045f
ep_bytes: 686eaee1bf5a01fe83ec04c70424d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lahy also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.12c91270057e0635
McAfeeGenericRXGJ-XZ!782F7B0A0DC0
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.0057e0
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lahy
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cee2a5
Ad-AwareGen:Variant.Razy.870640
DrWebTrojan.Siggen14.7487
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.bjld
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3313E44
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
ALYacGen:Variant.Razy.870640
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
RisingTrojan.Injector!1.CD26 (CLASSIC)
YandexTrojan.Copak!OdM3X9C9g9g
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lahy?

Trojan.Win32.Copak.lahy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment