Trojan

About “Trojan.Win32.Copak.ldsw” infection

Malware Removal

The Trojan.Win32.Copak.ldsw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ldsw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.ldsw?


File Info:

name: 81FE2EDB1511FE338D7A.mlw
path: /opt/CAPEv2/storage/binaries/70dde5eb6d7ec66d741c2c7d0410f61c26a3adccd7942d0e8e0ae653a40e44d7
crc32: A3B2C810
md5: 81fe2edb1511fe338d7ab8930e52de30
sha1: cf8274681019594df58456769971c5d90db713f2
sha256: 70dde5eb6d7ec66d741c2c7d0410f61c26a3adccd7942d0e8e0ae653a40e44d7
sha512: fe5377e12cff54939df0a4cc77c15f101050fd9882279af6f2109fc21fffeff45977cb0bbb4eccf21fb3532cf83318c922f74089dd54195989f73b7255b53d7a
ssdeep: 12288:RZN8BEPyAO54CKM950Eb354CKM950nnuax/U4CKM950Eb354CKM9505:RgqPMf8s37f8nIf8s37f85
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T186E4DF350A83C61DEA0C7C31EA4C659848EAA15E66FE42154F7D7E33DB8B30AD8835F5
sha3_384: d7aa88004e3b57007f360fa622499b1befdd5e5cf3322d5a9f5ecb27e47d954c0f5fe2c16d1de08b5725c1089e328efb
ep_bytes: 682f7922788b1c2483c40468d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ldsw also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.81fe2edb1511fe33
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.ldsw
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.jc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.blrv
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333AF2D
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!96055ACB1B82
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
CylanceUnsafe
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazojkPvuvL9a+t89AoDoM+cO)
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.OuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.b1511f

How to remove Trojan.Win32.Copak.ldsw?

Trojan.Win32.Copak.ldsw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment