Trojan

About “Trojan.Win32.Copak.lzec” infection

Malware Removal

The Trojan.Win32.Copak.lzec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lzec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lzec?


File Info:

name: CA4923EB853CD5BA21F7.mlw
path: /opt/CAPEv2/storage/binaries/607a65d9b57663e927f7bda647c719a71c4feb3a0dd5a7b63a8d092e7d18326f
crc32: B76E26BE
md5: ca4923eb853cd5ba21f7ced1e45ca5fc
sha1: b66f67a995d37f9e9a9a1e2a9a221332c98af1d4
sha256: 607a65d9b57663e927f7bda647c719a71c4feb3a0dd5a7b63a8d092e7d18326f
sha512: 1925308f780212d034a4578e49bff085976fb040e7de4296f2e345270bbc3fea07eb48fee4d92d93d9e9a48e848e2b2a48f4f5b7eb2a2f9e7f4cb25f550bd6b1
ssdeep: 3072:S9qsBC5uayTEgwT0WFUHZEOmFfgraoFVi6ERz+OBC6WvjXYdQfS77jvB9uLE:Zskew0VmamYE9RBIvzxuvvnug
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T125F3CFD152071ABBCE252539868E13DC639C81FDBCFA1855CE63CCC068786D48FA627B
sha3_384: 862822e4e8d45e4fbadc33701483f62c964b87f79cc1d1e6962c9ff87f3401d0ed992c74d0610a764bdc9c6cfdf7b923
ep_bytes: bb9037dc6229ce81c139dadb1b68d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lzec also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.ca4923eb853cd5ba
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.b853cd
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.lzec
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazpKOziem/EqsQkabppDhMKq)
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33ADE39
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt
APEXMalicious
TencentTrojan.Win32.Copak.wa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lzec?

Trojan.Win32.Copak.lzec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment