Trojan

Trojan.Win32.Copak.ldyn removal instruction

Malware Removal

The Trojan.Win32.Copak.ldyn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ldyn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.ldyn?


File Info:

name: A5C4197A101DBA46F071.mlw
path: /opt/CAPEv2/storage/binaries/1850ec855893235e67601335a909ea18893b3d3946427e07362ed5fa15a69e6d
crc32: DF458400
md5: a5c4197a101dba46f071f58f08699eb5
sha1: 8297054a15228aabe42f8ad356adeec9a5cdb2d2
sha256: 1850ec855893235e67601335a909ea18893b3d3946427e07362ed5fa15a69e6d
sha512: 122efebe675eb4f07ac9ab7288e85fd0f24a6ee3d491dda68401c1f766a9312106624a02249f56ff3ec885633f45b301788bf211b97e6841129d419e991dc7de
ssdeep: 3072:yjlK7PoIMlrn9D3FYF9hngqwKFhb2p8r14/rh1Wgx0PoOwRn:yUsI0npqF9dbFhb28Eh1Dx0P6Rn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18DF3D07B6C86BC41C69C0F74B0A3CB704A57981AE466D02AFBD3E6DA714D1CA07452BF
sha3_384: 81bff4c56756d1df77b9e9830f5c2b9ad540f0929117b0794907c61bb16735d8e6e04e9158c3bebd8c3b1977dc8a653f
ep_bytes: b993af9e5281c259db761f68fe0c43e7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ldyn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.a5c4197a101dba46
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.a101db
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Ifsc5sd-9932983-0
KasperskyTrojan.Win32.Copak.ldyn
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfd0b0
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.332C375
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!6C5FC277D85A
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazpGBOq3DRvebdHkeexiqIr8)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.ldyn?

Trojan.Win32.Copak.ldyn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment