Trojan

How to remove “Trojan.Win32.Copak.lcaa”?

Malware Removal

The Trojan.Win32.Copak.lcaa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lcaa virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lcaa?


File Info:

name: 91E44DA4ADDA0F26A22A.mlw
path: /opt/CAPEv2/storage/binaries/0574e6f95d60eba7ffdb04d12eb374493492f6d537806edbcf4c31cf7d22fb55
crc32: 0328D54B
md5: 91e44da4adda0f26a22aec51af5eea9e
sha1: 26cd0b7a2fcc189725395b96e6d6356506281980
sha256: 0574e6f95d60eba7ffdb04d12eb374493492f6d537806edbcf4c31cf7d22fb55
sha512: d355759458d9548f393a08a97865a6a4a81564ef4171b60f13702eefbfac80bf9fdd398a266e2ad8ba1db302bd93bd0442c7a30c610fe0659209844c3245a266
ssdeep: 3072:mskvyjM79/zI6O79U/h+3BT4kT6HxW9qId8eZaUKtzT:C6jMFz4BU/k9ARWV8SaUKtP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T116F3D0258BFE0083E15B8A3174C306DDC72A8AB3E565437ECB635C9B2DD01B57C4AA76
sha3_384: 01e81b684d859221966d40512279aa312710d280a4c52e5026deb25dabf1d30461bd6235e1bce1f89db451fb8266ac3d
ep_bytes: b92f2b43174668d885400021d6680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lcaa also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
CynetMalicious (score: 100)
FireEyeGeneric.mg.91e44da4adda0f26
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Razy.865537
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1321967
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4adda0
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.lcaa
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.865537
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.bltb
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3355961
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!FBB08F54EF7D
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrU++o5rFlkGKAxc2BTCyim)
YandexTrojan.Copak!eNpelfeSZ4o
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lcaa?

Trojan.Win32.Copak.lcaa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment