Trojan

Trojan.Win32.Copak.lmnt removal guide

Malware Removal

The Trojan.Win32.Copak.lmnt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lmnt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lmnt?


File Info:

name: 0D43B158A53BA85FFDA4.mlw
path: /opt/CAPEv2/storage/binaries/ea8748063d0a526650000ac851c72b147266af2fb390acb492ff9db63c78181b
crc32: FC12E6AB
md5: 0d43b158a53ba85ffda4cfd640744ac7
sha1: cde7d4cb2426492aa4939e523bd08e84e9f84854
sha256: ea8748063d0a526650000ac851c72b147266af2fb390acb492ff9db63c78181b
sha512: 7c01a375c726ea30cce7b30738008b4540c88d4c0ae3a882c6c248871c828e77746de613ce96b11626699d84588124553191c6ac0b229548205858df82f202de
ssdeep: 98304:4rwAmqxdS0wAlz6wAmqxdS0wANH9wAmqxdS0wAlz6wAmqxdS0wAk:4OsBTsBF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D036CFC002758066DC209475F129C2A0D66805E37DB5B73BBB96FC0169EF69B498AFF3
sha3_384: 9ed808c6928b4d94cb23fed061861a9fe696e39443e0c614c3c3125abb1935d6b921babfb9af074f99dc82e09550709b
ep_bytes: 83ec04c7042450a748795f81c0010000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lmnt also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur2.@xZ@IfSC5Sd
FireEyeGeneric.mg.0d43b158a53ba85f
McAfeeGenericRXAA-AA!0D43B158A53B
CylanceUnsafe
SangforTrojan.Win32.Copak.lmnt
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.73c210a9
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.8a53ba
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-9937441-0
KasperskyTrojan.Win32.Copak.lmnt
BitDefenderGen:Trojan.Heur2.@xZ@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Trojan.Heur2.@xZ@IfSC5Sd (B)
DrWebTrojan.Siggen14.7487
ZillyaTrojan.Injector.Win32.1348298
TrendMicroTROJ_GEN.R002C0DAU22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S + Troj/Agent-BGOS
JiangminTrojan.Copak.bpvx
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Injector.fdzyp
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ViRobotTrojan.Win32.Z.Copak.5308448.DX
ZoneAlarmTrojan.Win32.Copak.lmnt
GDataGen:Trojan.Heur2.@xZ@IfSC5Sd
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaAI:Packer.C946CB351C
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAU22
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.lmnt?

Trojan.Win32.Copak.lmnt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment