Trojan

Trojan.Win32.Copak.ldtd removal guide

Malware Removal

The Trojan.Win32.Copak.ldtd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ldtd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.ldtd?


File Info:

name: FD0020B7E19843086D43.mlw
path: /opt/CAPEv2/storage/binaries/7592f9388f6096e307052609a6aa4a3738063775334806df577c5d356e7ab3b1
crc32: 73C96A9D
md5: fd0020b7e19843086d430ca48ce1684c
sha1: 639af4211da83b828fee6e4265dc27157e13d1e8
sha256: 7592f9388f6096e307052609a6aa4a3738063775334806df577c5d356e7ab3b1
sha512: 99729e33ef0a650a565be81c781f92cf8c3fb33e7574e58020f71cb1ae7e60b90f0572b34aef9b39f59b038d80665ef5db63ad97edc77906ab0ddec829b4055b
ssdeep: 24576:/uRJbE3kJiktEOQPExbFFRvuqJXJEOQPExbv:/6dE3OEIXFRBJXJEI5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BA0512B9E7255793D5490EFAFDF4F0E48AB8B48279FD381F4A8B784429C583C60058E6
sha3_384: b985905d0ae15712103e0679c158d3b901d34f3957907bd828f1076535f17fa93385a18b4a197a04d972bfcc9a165f3d
ep_bytes: bfd305846681eb63c9bcb801f668d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ldtd also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.fd0020b7e1984308
CAT-QuickHealTrojan.Copak
McAfeeGenericRXGJ-XZ!B8551C3DD527
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.DD48F0
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aOhSZ5
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.ldtd
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce8aea
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
JiangminTrojan.Copak.bmgm
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.3388EFC
MicrosoftTrojan:Win32/Glupteba.DB!MTB
APEXMalicious
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
ALYacGen:Variant.Razy.870640
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4210493195
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqCpf2QWDbTXJ7RPznfYL4T)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.7e1984

How to remove Trojan.Win32.Copak.ldtd?

Trojan.Win32.Copak.ldtd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment