Trojan

Trojan.Win32.Copak.qavw malicious file

Malware Removal

The Trojan.Win32.Copak.qavw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qavw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qavw?


File Info:

name: 287270F42382756BEC52.mlw
path: /opt/CAPEv2/storage/binaries/bb7c7befda2dd6cbd6ad0196d673c8da768f6e9540f3a1329eeb0c1b44bf96bb
crc32: 281BF3FE
md5: 287270f42382756bec528cc6655c01ca
sha1: 4c1024acf008bb2f94665f860e8ade2cf359920e
sha256: bb7c7befda2dd6cbd6ad0196d673c8da768f6e9540f3a1329eeb0c1b44bf96bb
sha512: c6c5aa5198edaf0044048d419328c7f85d1820aeaa39236bcaba620e20d1dedf293b4834d8139c2747f2a8d8e5e439cc693213d8dcff19d0ca3cadff6f67bbfa
ssdeep: 1536:HyX+pSFhczLzZol1q+4o85pybO8tN6+UD9xxHm1mXpSRENwQCDFaL4FNl44:HyupShSzZoPz8vvzD9LHmQM1DYEG4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T109A3BE244E10C32DEB16CAB85B957F1238E337FA18650AD6B34E5ECA2574E34DCD4DA2
sha3_384: b35ebf43f1a3820be655c03e7916c8df834953915a3fcc79a82732a82fd133336bf0ed8d2d25beb90362faf017bdfb18
ep_bytes: 68bdf7d81c5a21ff09c083ec04c70424
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qavw also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.287270f42382756b
McAfeeArtemis!287270F42382
CylanceUnsafe
SangforTrojan.Win32.Copak.gen
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.6263fbbd
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.423827
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qavw
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAV22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.nc
SophosMal/Generic-R + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.865537
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3337196
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD3501
ZoneAlarmTrojan.Win32.Copak.qavw
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.guY@aeSC5Sd
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DAV22
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qavw?

Trojan.Win32.Copak.qavw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment