Trojan

Trojan.Win32.Copak.lcws information

Malware Removal

The Trojan.Win32.Copak.lcws is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lcws virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.lcws?


File Info:

name: 7815884F8F300A3269AA.mlw
path: /opt/CAPEv2/storage/binaries/78338ff665d8c6630de2d0995eb0320a78beea727934bab680078021b3f39d65
crc32: 1A861270
md5: 7815884f8f300a3269aa84ca2d3a5111
sha1: b68b1a4332b305c319d593ea358223c07c920c1f
sha256: 78338ff665d8c6630de2d0995eb0320a78beea727934bab680078021b3f39d65
sha512: 73e7ae7a5bffff2c5d43a6b77aaf2a2f0705a88afa5d688e3a84f435d12a961a43d13cbdb46c57b4e76fdcd020d44f9a5bcb0aabbee4fafec52bf6b8a8a4b5d5
ssdeep: 24576:vtG31XKGffmnuNS33p1bLHu8DFyqm4afmnuNS33p1bLHu8D:UhtfmnuAH/LHu8Dnm4afmnuAH/LHu8D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T191050175E3C2D112E73940BCBFB2A44352552A8F83E283DBA624EF8434D5EC41995FE6
sha3_384: 2a5973906992c68d2b50f9c5cf50011f93a9de1966e499c9951da23d1796a453d7755147e1e1cc1a3acd7c560fb7c5d2
ep_bytes: b971e2a27129db81e89922f40968d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lcws also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.7815884f8f300a32
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.f8f300
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9917603-0
KasperskyTrojan.Win32.Copak.lcws
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfae3c
Ad-AwareGen:Variant.Razy.870640
SophosMal/Generic-R + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA622
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.870640 (B)
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.bneu
eGambitUnsafe.AI_Score_97%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.337699B
GridinsoftRansom.Win32.Wacatac.sa
APEXMalicious
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGlupteba-FTSD!7815884F8F30
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
RisingTrojan.Injector!1.CD26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.lcws?

Trojan.Win32.Copak.lcws removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment