Trojan

How to remove “Trojan.Win32.Copak.lbdt”?

Malware Removal

The Trojan.Win32.Copak.lbdt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lbdt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lbdt?


File Info:

name: F17FEBF702A585B956F8.mlw
path: /opt/CAPEv2/storage/binaries/7a6e3f8b21255cad7353ac46d6f50ca2d4be0313c52be3ea8dc81bb23785bdc0
crc32: F533C00F
md5: f17febf702a585b956f88b8353f633c5
sha1: 226cc8f06e42aa9736dc4784ba810f68d5944a5c
sha256: 7a6e3f8b21255cad7353ac46d6f50ca2d4be0313c52be3ea8dc81bb23785bdc0
sha512: 48af27d0bccb9f7aed0d324ad4e8d2dd617b29ffc65aa8a264914bd3b3137e69cb0fb86a7de8b54638800ad418fc3fdea37b144af40c2a04a73a7db969459abd
ssdeep: 3072:t9vEWw0XlDTBkCvd9Kk3BUUOGkXMJX+B0PCmtduMTPB0CE4R+:tKWw0ZBT9KxSPCyduYg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1ABF3CFCD7A0AF930D57224BC2353D2C3DABB121A78D2D54987465F7B4AA4C1CF3D6A22
sha3_384: 2d5d7c569fde2ffe5bd43f7eb0c84a427f597fa255b92f80c56e6924e467b27c1c38e7e72df9f659796c8a0a2ab87756
ep_bytes: 68d6e682b45a09c768d885400081eeaf
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lbdt also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.f17febf702a585b9
McAfeeGenericRXGJ-XZ!18877335AB36
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1322205
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lbdt
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
SophosTroj/Agent-BGOS
F-SecureTrojan.TR/Crypt.XPACK.Gen
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bmqa
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazo7SSF2JvZVH/s8JRhtdO6V)
YandexTrojan.Copak!cnXy/pO7DSU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.702a58

How to remove Trojan.Win32.Copak.lbdt?

Trojan.Win32.Copak.lbdt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment