Trojan

Trojan.Win32.Copak.qaan information

Malware Removal

The Trojan.Win32.Copak.qaan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qaan virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qaan?


File Info:

name: EC19AAA0B4E8449F33FA.mlw
path: /opt/CAPEv2/storage/binaries/45d31f898d81fa0b5933e2931d26a6dd5fa6ec4a085ab258ec1678be75fec7aa
crc32: F032DC2C
md5: ec19aaa0b4e8449f33fac982a62c32aa
sha1: c304943b455f34a32e24497d8684a722fe7b0c4e
sha256: 45d31f898d81fa0b5933e2931d26a6dd5fa6ec4a085ab258ec1678be75fec7aa
sha512: 4681f69b855aee55c5d5f5fb1f5d8c2099d0f1308858a4764eab6457fad9e80547dfc41a9da8e91e4c2bff85346625826d7c9eab71c3a717389522277beb2c36
ssdeep: 3072:JvvM8LJNPEDJq6luW3yGrUvaHR91XfON2iEhcabFZCRSt9a7qNH+903W/cAkr:JvvvlNPEDQWuWC3ypE6LvCwto7ce9AAA
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10A149C074E447D31EA02083C6B8826AC7D28790D9B5BE1DD59208E6CD75C7F836DE8AF
sha3_384: 6575acc166cdee670dfb02a9ee1d740798c6926f00eff1df9f9bbe7622066398b7b5f81120e74c2b97d947d94c027c19
ep_bytes: bfbbe8650681eb729a382e29c968d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qaan also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ec19aaa0b4e8449f
McAfeeGlupteba-FTSD!EC19AAA0B4E8
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1441867
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.0b4e84
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Copak.qaan
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.865537
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazob3CXSjm9Id+C5DcjhBsc2)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R03BC0DB322
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3344BC8
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.muZ@aeSC5Sd
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R03BC0DB322
TencentTrojan.Win32.Copak.wd
YandexTrojan.Copak!DYqqk2O2rMg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qaan?

Trojan.Win32.Copak.qaan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment