Trojan

Trojan.Win32.Copak.lbbm removal

Malware Removal

The Trojan.Win32.Copak.lbbm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lbbm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lbbm?


File Info:

name: 76D2B925F31E0ECD35AD.mlw
path: /opt/CAPEv2/storage/binaries/e5720d39a34415a49fd6328c2c0f4b524b3c84d626b458eda2f95d0ee59fdc8e
crc32: 1A2FD40A
md5: 76d2b925f31e0ecd35ad76335cfd4934
sha1: bfc35cbf31d3492ab7fe4f6324ef89d96949bfd9
sha256: e5720d39a34415a49fd6328c2c0f4b524b3c84d626b458eda2f95d0ee59fdc8e
sha512: 2fcf919e566aee57bcc3da465c08fc0d8e760cbfb749494d1d11ee518becf8d8999e723a7f2d797860a1070c9a1ad6b8395ee259beae05d3e35bb8eb34b83731
ssdeep: 24576:BaHU3JWx18IcA+LEZs4U/JUi1M+LEZs4UZ:BaHqWbSoq4U/1oq4UZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1830501383D5A04FECF3C26B015AFB0F8D444C813AD7AA4E65943E749B8D6B7896878D4
sha3_384: fc9d023690cfb1e119392888ffed21a966c5c34899d6b2def753af9e06b1bad2fc270b2ce11c42109a908fa6a53480a5
ep_bytes: 68798957155b21ff68d88540004e4168
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lbbm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.76d2b925f31e0ecd
McAfeeGenericRXGJ-XZ!99C1FEDA8578
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lbbm
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11c7afaf
Ad-AwareGen:Variant.Razy.870640
SophosTroj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Razy.870640 (B)
JiangminTrojan.Copak.bjld
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.33AC6D7
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
MalwarebytesTrojan.Injector
RisingTrojan.Kryptik!1.D284 (CLASSIC)
YandexTrojan.Copak!OdM3X9C9g9g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.5f31e0
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.lbbm?

Trojan.Win32.Copak.lbbm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment