Trojan

Trojan.Win32.Copak.lbht information

Malware Removal

The Trojan.Win32.Copak.lbht is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lbht virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lbht?


File Info:

name: E77280F789EAEDB0666E.mlw
path: /opt/CAPEv2/storage/binaries/ae4bb1413b27a1e28aae8f0b4b49b40cc2491b9ab397dbe0e76f7add36904ed8
crc32: 32782880
md5: e77280f789eaedb0666e5e3ec48580fc
sha1: 9b698732f868140af2c68c53dd94999e8a9a4f61
sha256: ae4bb1413b27a1e28aae8f0b4b49b40cc2491b9ab397dbe0e76f7add36904ed8
sha512: 43a294931b336c5c8dd3cb42c7224717f5279a9ce56def72213d609f114e85d0dc9f25b1a0650789d075da1cbc0aa11ffa1b0189eeaca3a004b9a949f159e3f1
ssdeep: 3072:YUoHDRqags3jOgt5GudhnxnIhNVXooPdIH8vMf41AF3QX08d98:hoHQLijO+GuNsNrIlQ1kQEY98
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11CF3CFDBE56B29B2E2395975C7864CDC71A4371F6B8A401F473B360E2242A3F0E6117B
sha3_384: a3fc515b081cc8cbd28e962a9f84ef72e3b2e1362984150b3576275b64fba2b56efe3714dc7c3f4aa4b160a88fe482cb
ep_bytes: 6851a519fb5b81c1cb1c5dae83ec04c7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lbht also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.e77280f789eaedb0
McAfeeGenericRXGJ-XZ!609DAA48E13A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.789eae
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.lbht
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce9073
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.900994 (B)
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.330E893
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
MAXmalware (ai score=83)
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.lbht?

Trojan.Win32.Copak.lbht removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment