Trojan

About “Trojan.Win32.Copak.lgdw” infection

Malware Removal

The Trojan.Win32.Copak.lgdw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lgdw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.lgdw?


File Info:

name: 9FA1785A5AC3755447BF.mlw
path: /opt/CAPEv2/storage/binaries/9b7c25db86c60f707b44bfd142c9d1a73bace95645c0e39625bca7ad05caa71d
crc32: 996A8C60
md5: 9fa1785a5ac3755447bf8c281e72cd97
sha1: b936ab4f74f946eabaee41a896e7bcaeec7f978b
sha256: 9b7c25db86c60f707b44bfd142c9d1a73bace95645c0e39625bca7ad05caa71d
sha512: 462713c3256cc2a78bdb36a458fa97426026fb8fca3a36bbcc1dd50159e7a39a8b1e084bc60a5726f36228af35ace0bf83b42366a248ae80b2667aa91509ab44
ssdeep: 3072:okz/B+jqM36MvEsCjXU7otMLkYpxCgkEJmjDJuIFvbsKBuDJGw7tyMvsrz:PY/6Xs0U5sjDJuIFvbsKBul5QMErz
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EAF3E1D524A27E60D296D53587A0D4CEE3AB3D1A6FD32C1A4A7409D92313DCE0FC4ABD
sha3_384: 267cd19172079e4d4f81b285c01ca72b0e71e696386ec590d4cebe57d248ef0f27ded79b2a0b7e49eee9e38e50a40422
ep_bytes: 688539be3a5983ec04c70424bc286b3c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lgdw also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.9fa1785a5ac37554
McAfeeGenericRXAA-FA!9FA1785A5AC3
CylanceUnsafe
ZillyaTrojan.Injector.Win32.988722
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.a5ac37
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyTrojan.Win32.Copak.lgdw
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cee2a2
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bnwu
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.337F195
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazoC4YsfMNF2i3unQBlSxQd1)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lgdw?

Trojan.Win32.Copak.lgdw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment