Trojan

What is “Trojan.Win32.Copak.ldqa”?

Malware Removal

The Trojan.Win32.Copak.ldqa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ldqa virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.ldqa?


File Info:

name: 1549AF65ABE309093FEC.mlw
path: /opt/CAPEv2/storage/binaries/868d9174522fab7609a9927d4745c948734c93955ed4a013126e7be43f60ac14
crc32: 4EF615C1
md5: 1549af65abe309093fec27d89d990476
sha1: 4e09089335388c01e452eff640e864dc3efff22e
sha256: 868d9174522fab7609a9927d4745c948734c93955ed4a013126e7be43f60ac14
sha512: 867b8b48a333a6425010d6285256248c8258c0ce26e061e30786a0937ed97e7cf4b320ce06a59fad64cd08f5a186273f2faa17885b99e6c6d603d8eb5f52c3cd
ssdeep: 12288:1MmwLHp0uEmCFesp7HH1ZUPDusJX+9YC1m4cR8DVlhjtZwyH1ZUPDusJX+9p:1uLCgyHoDuj9+4c+rhjtZwyoDuj9p
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D90512C7E28D2B2DDE50B7300FB9CA4ADEB58B8CC01B366E395414639F5125670B47AB
sha3_384: 2522bc68c57f60401d670599b7ccce4ef6b62b5e570cccdfb03055735d0c5dc81c1573ec6fea285d02a602eaa72750bb
ep_bytes: 682988a8235a83ec04c70424d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ldqa also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.1549af65abe30909
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.DD48F0
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Itwc1te-9917154-0
KasperskyTrojan.Win32.Copak.ldqa
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.870640
AvastWin32:Trojan-gen
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazogyoZ5ofb1iqCV6JpE0HTg)
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
JiangminTrojan.Copak.bldm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.335881D
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.870640
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGenericRXGJ-XZ!075F4E1A3558
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
TencentMalware.Win32.Gencirc.10cfa3a7
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/GenKryptik.CTNW!tr
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aOhSZ5
AVGWin32:Trojan-gen
Cybereasonmalicious.5abe30
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.ldqa?

Trojan.Win32.Copak.ldqa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment