Trojan

How to remove “Trojan.Win32.Copak.lhsw”?

Malware Removal

The Trojan.Win32.Copak.lhsw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lhsw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.lhsw?


File Info:

name: BB1C1CD0BA15C2189754.mlw
path: /opt/CAPEv2/storage/binaries/de40c9b01face80b89dd96371b811b9ae6631dc6b76509933180f947441d6a2c
crc32: 7AFAA6D5
md5: bb1c1cd0ba15c21897547ab22c6a17c4
sha1: e438e128d4e7001c52801c9207e306d26e2d818f
sha256: de40c9b01face80b89dd96371b811b9ae6631dc6b76509933180f947441d6a2c
sha512: 9a7e5c62b585907b03023ee43d0db9d4bc361083cab65d955a0c7aac50559330c8b2671f7770e608a6498fe1b1f8c7245515c9c0f3ee7d4203b4a1d07d37c080
ssdeep: 12288:DR5pHZqmNjGNpHa2Me7F55KKnBf+naXZoh+YLdPKjVHYwQRDvCAotEOa2Me7F55u:DR5pENp62tHInakR/wcCAotg2tHU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19005F164DAA207FFE021A97369A5ED97AD60E61E33670075D60FDCC1EF3110906AB0BD
sha3_384: 0505934ccf9c2396fa62762fd79e91fbfd744cae638765121853959d0c15e81daf663b15ea7cb36b4b97d2cce0ed9746
ep_bytes: b81237fb4a83ec04c70424d885400081
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lhsw also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bb1c1cd0ba15c218
McAfeeGenericRXAA-FA!BB1C1CD0BA15
MalwarebytesTrojan.Injector
ZillyaTrojan.Injector.Win32.1310560
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.0ba15c
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9932938-0
KasperskyTrojan.Win32.Copak.lhsw
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.870640
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfaee2
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.33A29A3
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
CylanceUnsafe
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazpr4ZoCQ+80cjJ4epA/EV9G)
YandexTrojan.Copak!769ZM+LYOW4
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lhsw?

Trojan.Win32.Copak.lhsw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment