Trojan

Trojan.Win32.Copak.lbrz malicious file

Malware Removal

The Trojan.Win32.Copak.lbrz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lbrz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lbrz?


File Info:

name: 53E294C210C7313B1915.mlw
path: /opt/CAPEv2/storage/binaries/dc5f78aea9056b0eab095febf3c1ccc7fcd46cc2abebf1945edde0d168c2ab0a
crc32: B86909B3
md5: 53e294c210c7313b1915b6133d8d75c9
sha1: 927967444bb31db6589395833ad43e12dc4674e6
sha256: dc5f78aea9056b0eab095febf3c1ccc7fcd46cc2abebf1945edde0d168c2ab0a
sha512: dcd1fcd41d8ee60e412618782874ffd3b6ab177d13d59582cf0837e84b2a114bf542906e359f139bc084a09f180de6fc7c8fae9cc9d6fed45a5ab065e8c2472d
ssdeep: 3072:CFn0+0WPPDtpF5hJaksp1XUz/BVFaUugkwQ:ClnppFY1Xa/BvJM7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D0F3CF374D722175EDCB087C92430C636C7412D732DE98ABC2A45D9B26BF388D5BA96C
sha3_384: 57b74a81d1aa06b3123e3848f1ab9690ec6687827689d064de46b5e0ffec2bc09a397c7d5ab3a58c8ad89182daa16975
ep_bytes: bb144cc29681ee0100000009cf68d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lbrz also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.53e294c210c7313b
McAfeeGenericRXGJ-XZ!297C19D4A610
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.lbrz
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce7bc7
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.865537
eGambitUnsafe.AI_Score_98%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.336721D
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.210c73

How to remove Trojan.Win32.Copak.lbrz?

Trojan.Win32.Copak.lbrz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment