Trojan

Trojan.Win32.Copak.lamh malicious file

Malware Removal

The Trojan.Win32.Copak.lamh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lamh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lamh?


File Info:

name: A68EC291C2B05643068A.mlw
path: /opt/CAPEv2/storage/binaries/3e8e6d36ca6cec4ad97d58abaaa613c119dcb30037e745150e1e44b16fa9e172
crc32: F267C75E
md5: a68ec291c2b05643068ac8a930446464
sha1: 8a2f9a026b0d2af314042293fe06d89b3b9dd359
sha256: 3e8e6d36ca6cec4ad97d58abaaa613c119dcb30037e745150e1e44b16fa9e172
sha512: 5728e800b8637e1f7e8841e27bfe9406be21d7864f8ae223dad7278529045bd6baa6d0b1b76a656ac35070e5b040e9ddc8e963e2f00df47e14a433c60d101fb2
ssdeep: 6144:KuVi7+EsUPEXkUKiikPff7/hIwWIQG1eqTx5f/NuM83mDi7/hIwWIQw:7VMUJXPHTff7ZIwWg11FB/NJYai7ZIwb
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10E64CE297441125AE945EB34B7C01079229BC72A7D35AFE79F2D347A8CBC0C7B2749E2
sha3_384: 4bc92456f7bfe45a0ae608b1ca8be11d99cddae79864db2c496a14962cd079ab0807cf3ede2cc5284425c274fdfbd57f
ep_bytes: ba86f0a46568d885400046b9cd99dfec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lamh also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.a68ec291c2b05643
McAfeeGenericRXGJ-XZ!E9EE46AC50BD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.1c2b05
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.lamh
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce74fb
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosTroj/Agent-BGOS
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bjvv
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.336DC74
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lamh?

Trojan.Win32.Copak.lamh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment