Trojan

About “Trojan.Win32.Copak.qacm” infection

Malware Removal

The Trojan.Win32.Copak.qacm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qacm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qacm?


File Info:

name: 79F9BCE49B95F0C0BC86.mlw
path: /opt/CAPEv2/storage/binaries/53f3dcf26aada17582d14d04ec7837aad9c9f92ebe2e99c7fd965864e3833a51
crc32: D9A9ABC0
md5: 79f9bce49b95f0c0bc86f0d06761814d
sha1: 6abfa416877c23b60ea4d40de5e43facee42f181
sha256: 53f3dcf26aada17582d14d04ec7837aad9c9f92ebe2e99c7fd965864e3833a51
sha512: ca498478f7a6b4ab04cf2ae025c0083fff31788d178dbc97944aa31af24003ec7e9cc0b12963d51be6c45d13dbca3e809a8c2a7726383f8c66ad411ae712af66
ssdeep: 1536:BeEKCS3Y3amvK+nUeXLq2QSN2ogFZEYsOurk9JQ+HCj5/nqL3FdQE:vvS3YHD/XLqx5UkJxHgU7FqE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AE83D0A1A82B21F8E5784973D1F320AACEF76AC3E502209DCD6791D1654EB47DC6C9F0
sha3_384: 305760838bce09194ab50349742126ef2ffc518d2a7282f266b56bc31622a9fe4a2816e85f529014b2ce1fcd7ce07a63
ep_bytes: bab822007509ffbe46dea53268d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qacm also known as:

LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Trojan.Heur.fuW@IfSC5Sd
FireEyeGeneric.mg.79f9bce49b95f0c0
ALYacGen:Trojan.Heur.fuW@IfSC5Sd
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.d60888fc
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.49b95f
BitDefenderThetaAI:Packer.90472DB81B
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAV22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qacm
BitDefenderGen:Trojan.Heur.fuW@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Trojan.Heur.fuW@IfSC5Sd
EmsisoftGen:Trojan.Heur.fuW@IfSC5Sd (B)
TrendMicroTROJ_GEN.R002C0DAV22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Glupteba
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Trojan.Heur.fuW@IfSC5Sd
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!79F9BCE49B95
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Copak!FwGLpIKe6UE
IkarusTrojan.Win32.Injector
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qacm?

Trojan.Win32.Copak.qacm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment