Trojan

About “Trojan.Win32.Copak.lcbt” infection

Malware Removal

The Trojan.Win32.Copak.lcbt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lcbt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lcbt?


File Info:

name: 00C6C0E54AAA9F3D49F7.mlw
path: /opt/CAPEv2/storage/binaries/3e9d0d9a7168c2d7207bef067545161d69f77354a0c36a8e146beb669967727a
crc32: EB6F6D32
md5: 00c6c0e54aaa9f3d49f7ea9cf93618cd
sha1: 0ce5c5c040dadc13a87df59afae5870c147205d5
sha256: 3e9d0d9a7168c2d7207bef067545161d69f77354a0c36a8e146beb669967727a
sha512: b284b09282771dd2c992a7318a1026aa08e34526d58f027e1c8d27056513b0af10768c5669df1c308e00dfb6b5c126fea5a481336c07de15f97fe1d0a97ee888
ssdeep: 3072:MiMfg5MMnP73cEhY9ZqXJrdukGRV2yQ8LDwquf7DxV/bY3ro83:MiM4HP7sGvJrduAyQ6ufZsL3
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16AF3E04A7B078B1BEE75167A9E2E7390C81F3763542A278AF23F54275A8F17C447006B
sha3_384: 856619762354bbc0b2cd8d6d2f514294fd25a139bc52ede8ea926b4a1ec5b127394be7bc6cc56f0378d490cca1150318
ep_bytes: be0e1a594083ec04c70424d885400021
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lcbt also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.00c6c0e54aaa9f3d
McAfeeGenericRXGJ-XZ!060F84B71AFD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.54aaa9
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lcbt
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3345E42
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
TencentMalware.Win32.Gencirc.10ce9705
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lcbt?

Trojan.Win32.Copak.lcbt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment