Trojan

Trojan.Win32.Copak.lzsb removal

Malware Removal

The Trojan.Win32.Copak.lzsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lzsb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lzsb?


File Info:

name: 166950A7A593F0A961D6.mlw
path: /opt/CAPEv2/storage/binaries/eb7e3e57a4a942dcbef168c593330e0078f2d4862e48c1249a43992e4d2b6a3a
crc32: 4F5D0A90
md5: 166950a7a593f0a961d69233482f89e9
sha1: 192633754521727d2139338e18926138211082a6
sha256: eb7e3e57a4a942dcbef168c593330e0078f2d4862e48c1249a43992e4d2b6a3a
sha512: ac8e1ea238f6043b1b4f152df709d822b685f6f8e72a37116775c34d33ca66675b27d79ae46deb9f991356848a1fd5120d5900702a679dd034b5eb8e0abab419
ssdeep: 3072:abmk2GSTmnP6SgSUgXlw9Li3yUx+LWynxFY6LVLlcmKY/A5KRD6DmVuqk0q:aylGTnP6bNgXlMLbUxdynxFfLVpcmKY0
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10EF3CF0A878ECD8AF5FB44BDE93B4F901A548466D0931BDDBA0CEAF41188C75C453BDA
sha3_384: 17a3162bffd2b7bfae1b3c4240d601c6f48f60b2d327e29f9a4af89a8af5eaa4b63aea01a7b04e1def90201c02132e42
ep_bytes: be91f99a5381ef0100000083ec04c704
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lzsb also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.166950a7a593f0a9
McAfeeGenericRXGJ-XZ!3DABB038E79A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lzsb
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfdc2c
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bpwl
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3375BFD
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.7a593f

How to remove Trojan.Win32.Copak.lzsb?

Trojan.Win32.Copak.lzsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment