Trojan

Trojan.Win32.Copak.lwda removal tips

Malware Removal

The Trojan.Win32.Copak.lwda is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lwda virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lwda?


File Info:

name: 2B49650A513F0001D050.mlw
path: /opt/CAPEv2/storage/binaries/fcd1596e73d79241bbad688cbf8f4ace96c34cd4b060ec675b51c44b42709a6a
crc32: CFBAFAE6
md5: 2b49650a513f0001d05082a6b43853a1
sha1: 3171bef213e32b752b12018d2c02b8ee91a43ed5
sha256: fcd1596e73d79241bbad688cbf8f4ace96c34cd4b060ec675b51c44b42709a6a
sha512: 12dcf280adf533b465af8a67b2baba4e6af3946361c8ad0850e7f512d3ddd40e660667d173dd49157e22d63e560980d469219d38efcf6419712ed0c59dbea25f
ssdeep: 3072:RaT/q5sFZiAX1YmvogO7aSjE51Sgu6xxxwvWMSYl:gjysF1UgOekEvp9DwvWIl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FBF3D0755B0546A1D23C4AF1DFB045F88BEACD329D8EB5074E0B9430D7A01B5BAA41F7
sha3_384: 23938a6f0ab81ce6e52e6d53f21feb7dcddb9eca9f39cdae2c4ca591e3c58ef060b54019397437043d2acbed0035e402
ep_bytes: 68a94b72da5b4168d885400068001040
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lwda also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.2b49650a513f0001
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.a513f0
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lwda
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
eGambitUnsafe.AI_Score_96%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.334B182
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!35175DE77C54
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrcrHXbV74Mu7nzlrsFm1Kx)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lwda?

Trojan.Win32.Copak.lwda removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment