Trojan

Trojan.Win32.Copak.lnlr removal tips

Malware Removal

The Trojan.Win32.Copak.lnlr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lnlr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lnlr?


File Info:

name: 2E87B1C5B58801792769.mlw
path: /opt/CAPEv2/storage/binaries/6bc678edb8ec6c91fada8cc715ae0e1471a720e542430f34b119a651f4b80a4c
crc32: 22EFD966
md5: 2e87b1c5b588017927697eac29af3e4e
sha1: ef8a515e3406d3b2e8ef65c39a0207678330c35f
sha256: 6bc678edb8ec6c91fada8cc715ae0e1471a720e542430f34b119a651f4b80a4c
sha512: 75ce764cfb8d84c56d243a2a16a25d05f5ad64938029f5b780df4a77021522a00093f1d086f7a7f3359c97f1e8d1a0f2b18a24da7118f3b97a103d4e8cf77455
ssdeep: 3072:t/vy0RUYv/rrTVsmUzEkqTFF9pbbEYXPgJhHWNnuKEbYe358xDm+P1ZLKQEMgF:5vSYvjVU9uFFnbJXPMHWNnuqU+s4gF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BDF3CF087C0B4468FDF9D4BA9A960EA7967D05627F21545B8031B368FD83238F7F8C69
sha3_384: 4cc0d73cca3e65420231c3e08dfe7b2a0cb08d0241886ae9b27af81e8970b6ba3cd95174761d98aa9703d776933a6de6
ep_bytes: 68b9ba342b5b81ea9b0c714021c168d8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lnlr also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.2e87b1c5b5880179
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.0a9e288f
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.5b5880
BitDefenderThetaGen:NN.ZexaF.34160.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAA22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.lnlr
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cfcf55
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
TrendMicroTROJ_GEN.R002C0DAA22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bnvq
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33A5313
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!2E87B1C5B588
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.lnlr?

Trojan.Win32.Copak.lnlr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment