Trojan

Trojan.Win32.Copak.qarv removal guide

Malware Removal

The Trojan.Win32.Copak.qarv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qarv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qarv?


File Info:

name: 0D9A95F2D1C337A7568A.mlw
path: /opt/CAPEv2/storage/binaries/ebf0caaace75c0c940418ee24eaff6e128fc71bbd1803d544c13c37a50d5161f
crc32: DF1C78E3
md5: 0d9a95f2d1c337a7568a372b34198f9e
sha1: e73fb26d766205b3ed1ae73cc9bd6df30f7d762d
sha256: ebf0caaace75c0c940418ee24eaff6e128fc71bbd1803d544c13c37a50d5161f
sha512: 7075ddf091d132e7e4dcfc95f8f1ad5cf77bc077d3fe9514d38b3f16a33fc4b016cd277aa30944256c03f895697a4c76a2f7ca34937cd08ad8c5eb7422d1819e
ssdeep: 6144:py8NT69nTqxuYwmKZ98jt5oWteVnZgV3SVUFsLNfU8oN98jt5oWteVnZgV3V:lN+9TRm4Gt53sl2VC6FANWGt53sl2VF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10764BEC2CED63A16F841CFF5D9502EC5B138A69235F5322AFE44463A88B0E4E4774E6D
sha3_384: 562a2513ad827ff8f07a13f475eeed46448a29cd4eb044f7b8cea5e138b8ff710dfb121d8ba9d232e9929d725eb2eaf0
ep_bytes: bad890b8d181c61b5d2c2268d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qarv also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.0d9a95f2d1c337a7
ALYacGen:Variant.Razy.865537
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.f7ef0d45
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.2d1c33
BitDefenderThetaGen:NN.ZexaF.34182.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB222
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qarv
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Variant.Razy.865537 (B)
TrendMicroTROJ_GEN.R002C0DB222
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
SophosML/PE-A + Troj/Agent-BGOS
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.35199AC
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=84)
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Copak!Sj0DzRZEOCU
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qarv?

Trojan.Win32.Copak.qarv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment