Trojan

What is “Trojan.Win32.Copak.lcma”?

Malware Removal

The Trojan.Win32.Copak.lcma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lcma virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lcma?


File Info:

name: F2B34B1283C7F0C84A69.mlw
path: /opt/CAPEv2/storage/binaries/97b61cc8063318a367495ca458fd36b75cb3619f9d3acb7e1458999a62426a5f
crc32: FDE22B10
md5: f2b34b1283c7f0c84a69d9bfb149097d
sha1: 6a1fb1390d6828a323960629d63a8458e8ce81de
sha256: 97b61cc8063318a367495ca458fd36b75cb3619f9d3acb7e1458999a62426a5f
sha512: 3701176a9450472a30c84f5317e156910a330894b7c19f6e2c86fcf1b435cd098a042d6c5d01c7fe062525273230ea2a535fa2d4defa243f0808d1cfaa52531d
ssdeep: 6144:IWO9Rnd7ra+CxNYO3Qyl9Lu0Sl6eEL5t/jDtHmjUHBTUK2392koUKwSDIo3Qyl9Z:NUZcxOOAyl9LdSl6eEL5t/jDFmIHByNY
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12564CF0752C23365F070B8BFC6544FC36E68E29334E761DBA3B8098D263D55221BAB5A
sha3_384: 0b5b4923a4ea3be6ead2cd2363d5b55ffa20eb3b41878e5a508358883fece05ec428c0b4ea468a9d8f00250906f8c6c9
ep_bytes: be2bf0de4d83ec04c70424d885400068
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lcma also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.f2b34b1283c7f0c8
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Copak.lcma
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10ce7f59
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.bmgj
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33555A2
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!CD48442A071A
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazq2z/yTBouBqgBodPiqjrQy)
YandexTrojan.Copak!bQb6X+TiS2U
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
AVGWin32:Trojan-gen
Cybereasonmalicious.283c7f

How to remove Trojan.Win32.Copak.lcma?

Trojan.Win32.Copak.lcma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment