Trojan

Trojan.Win32.Copak.nqvs removal guide

Malware Removal

The Trojan.Win32.Copak.nqvs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nqvs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.nqvs?


File Info:

name: C39B85CD5DA29AE65A4D.mlw
path: /opt/CAPEv2/storage/binaries/ad4d1c605a585671150696d4b4f197f491726ed8afe26a48c08477de9757944b
crc32: 7C3FB147
md5: c39b85cd5da29ae65a4dc1496aaa931b
sha1: 77333cf40450ea1a494139b825ae7401f823af72
sha256: ad4d1c605a585671150696d4b4f197f491726ed8afe26a48c08477de9757944b
sha512: aab2dea0008bdc87c37dcd401cd44293eddfb05a513cdd518ef978a6946a2d3e48de3c67dfc4ecb956d1157ab1f18fdcfbcf25104bc2b8a130bbe5bf7366836b
ssdeep: 1536:mtgreGsz3qLqLaFncYwDMhrbcln9mtMv2AFgXcSm0E:mtiv9cYiMhQ9T9F8dE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14683CFA3C8873CCDF5725A3C5B4B56C5965F402B5084283BCBAAF5A979675303EB20F2
sha3_384: 56cbb1a1bc2cbb0b0722b97058fabfbeabf51006cd9a30c888e7506293ed5b2eeeb362e1c7d2356acc7cfccb46b7f0a8
ep_bytes: bad42cf85d4168d88540006800104000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nqvs also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fuX@IfSC5Sd
FireEyeGeneric.mg.c39b85cd5da29ae6
ALYacGen:Trojan.Heur.fuX@IfSC5Sd
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.9434964b
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.d5da29
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Iho3wxi-9883778-0
KasperskyTrojan.Win32.Copak.nqvs
BitDefenderGen:Trojan.Heur.fuX@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10ce71ad
Ad-AwareGen:Trojan.Heur.fuX@IfSC5Sd
EmsisoftGen:Trojan.Heur.fuX@IfSC5Sd (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAE22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.fuX@IfSC5Sd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Heur.E78EFD
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!C39B85CD5DA2
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DAE22
RisingTrojan.Kryptik!1.D284 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
BitDefenderThetaAI:Packer.4FFEE2691B
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.nqvs?

Trojan.Win32.Copak.nqvs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment