Trojan

What is “Trojan.Win32.Copak.qaxb”?

Malware Removal

The Trojan.Win32.Copak.qaxb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qaxb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qaxb?


File Info:

name: 127D7B65F4FD7516C7D3.mlw
path: /opt/CAPEv2/storage/binaries/dd306d3a859fe5a37273b4b0c934aff9a841647061f68177402b5c0806afbd6d
crc32: 90DCF60C
md5: 127d7b65f4fd7516c7d37df17e03887f
sha1: ca07373618807138d141fc9e59d92a40ffd8b5db
sha256: dd306d3a859fe5a37273b4b0c934aff9a841647061f68177402b5c0806afbd6d
sha512: 73bc60b7fe2cd9c1c2797ed9a635967d2c8d996ddd2ea2a33492f4ad32b0c3ec4de62cd1e4e99b4556b13df1b6ef2d8defdfabecc061bf9be9585c86a97a0386
ssdeep: 3072:qHX/C8OjMCoHLXn1PrqJWukaig+9yNMVpaWQ7RgWntVJpIIDprVWZ3/AasT:KtOwCoHLXNzuN+9yNVWxUFr4/ANT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13714023712EFD212F0145FB0AE4A36E55A3DF4D7B165E569E202C9B4D826247382FCB8
sha3_384: 355cdc2423871acb3e5093645dc8106aa1c0a4bf56e2e3e8fe296ad07bd774de5476171fdd655f814a40f589e5965932
ep_bytes: 685500090e5f81ee14594d6481e8e992
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qaxb also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.127d7b65f4fd7516
ALYacGen:Trojan.Heur.muW@ITwc1te
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.5f4fd7
BitDefenderThetaAI:Packer.C46C008F1B
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qaxb
BitDefenderGen:Trojan.Heur.muW@ITwc1te
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.muW@ITwc1te
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wc
EmsisoftGen:Trojan.Heur.muW@ITwc1te (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.dc
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34FC28B
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qaxb
GDataGen:Trojan.Heur.muW@ITwc1te
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!127D7B65F4FD
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazo+f2FKfkTQQHovQ+tY5xB8)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qaxb?

Trojan.Win32.Copak.qaxb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment