Trojan

Should I remove “Trojan.Win32.Copak.lvuu”?

Malware Removal

The Trojan.Win32.Copak.lvuu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lvuu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lvuu?


File Info:

name: FB425BB276F2C0689334.mlw
path: /opt/CAPEv2/storage/binaries/5a87dc10af7e1d6c1bfa7f2b94f2a748e95813de69b4d27f1ae871b8c54ee827
crc32: 7B014EEA
md5: fb425bb276f2c0689334b4e4c3263445
sha1: 26fe61073db22ed932b7e9578e3ed357111ae757
sha256: 5a87dc10af7e1d6c1bfa7f2b94f2a748e95813de69b4d27f1ae871b8c54ee827
sha512: 9fb16a4d8c9dac221fbd932baedf79cdc1faf31bc2612f9f15d47f0905d85b639d89a89aa0c9692b36f787fef5a918fabcd2a71b3192ed059345fb67a4371604
ssdeep: 3072:39jlNzK2xbCL0MfX+dIkqY+2iF1nmoJN5uhWzG3D7/YJuC5aHq6l98mmDVwPopYh:3PxPHdIkeTmQ5uh2WQEC5aK6lVApYbN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T167F3CF8E27C7D807C2044536E6621045DE875646CC872E3EEFBB9CE05ECA95DAB874B3
sha3_384: a9e58be5a0e4a285f4b3b8d6acd08a0f50177e5faadc99ec3a503018054b23defe1c9baa7011ad5db32638fb12482c37
ep_bytes: 684729291d5f83ec04c70424d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lvuu also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.fb425bb276f2c068
McAfeeArtemis!FB425BB276F2
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.a715847a
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.276f2c
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.lvuu
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cfb0b8
Ad-AwareGen:Variant.Razy.900994
SophosTroj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA422
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
Paloaltogeneric.ml
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.agws
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3371D56
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=88)
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA422
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Injector!rhUMGEgHvgA
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.lvuu?

Trojan.Win32.Copak.lvuu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment