Trojan

Trojan.Win32.Copak.lrdk removal guide

Malware Removal

The Trojan.Win32.Copak.lrdk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lrdk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lrdk?


File Info:

name: 361CBF011C821044561D.mlw
path: /opt/CAPEv2/storage/binaries/4f23073b868f3ac157a72f729bb6e9994f8586832de2ac394b80691ea72ae43a
crc32: 78BE3788
md5: 361cbf011c821044561d88b84b93c577
sha1: a20e9987276e059f3904638881bf62732286ca79
sha256: 4f23073b868f3ac157a72f729bb6e9994f8586832de2ac394b80691ea72ae43a
sha512: 6ccbb7a5e6f3dc21bdcd53d078ab54971fb3b75bbac2e5ef23b005b6fa9a4501fca968fcce3be70e425f4619e7c9f50d45c05b86404c61a8f906dd1beba161d6
ssdeep: 6144:Xeywf6ZSu2s7R18KAdUvN+XccvFxLt+3If6ZSu2s7R1u:ujf612sL8KAdUEX5vFxhXf612sLu
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12C64CE1C13A2CC02E0B843FB2C4568303FA64E617193EF16AA1AE5C4F7BD556759E7AC
sha3_384: 85ec7f9b46d6d637b39c0cb99af1c2b444ca1ea569fa816c03a12decd9c511b628d85248d1ecdca90f697d5d30fb2dd7
ep_bytes: 686f6f3c2b5f09f34a68d885400001d6
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lrdk also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.361cbf011c821044
McAfeeGenericRXGJ-XZ!60094A0CAB5B
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.11c821
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Iboz-9932960-0
KasperskyTrojan.Win32.Copak.lrdk
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
EmsisoftGen:Variant.Razy.900994 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.bpfm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3335885
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=84)
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrnYzcG4Ht2XTgp9nmrxGz5)
YandexTrojan.Injector!X2vdSodi4I8
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.lrdk?

Trojan.Win32.Copak.lrdk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment