Trojan

Trojan.Win32.Copak.qcfh removal tips

Malware Removal

The Trojan.Win32.Copak.qcfh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qcfh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qcfh?


File Info:

name: 1CCC748805406CD79776.mlw
path: /opt/CAPEv2/storage/binaries/a5da41289565c2fec7137c1e8b85e0730c76cbd486e8a8bc9a2c721b7c1fbb1a
crc32: 8AFFB536
md5: 1ccc748805406cd797767953ceefdaab
sha1: 4c94cc9f3b3dd1bb5e8bf24b4a83b303117aa4d9
sha256: a5da41289565c2fec7137c1e8b85e0730c76cbd486e8a8bc9a2c721b7c1fbb1a
sha512: 703053c99a7fd56971a31de36938a75f73777ae4c7004729b85168555ba64d50c22081340883aaa245dbf989423f7d0479e8733404b10bd2388048d8fde20ef8
ssdeep: 6144:FfUFEJvvjrTMf9SoHkDDKyrQIZdoKVQ8oAIppF4TMf9SoHkDDKyrR:FMFCvrESo0DKyrZ+Ai6ESo0DKyrR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1ED64CFBF69CF2278EEE10CB0525457EC8B383026ADCDA71D43E9115423955AE124EDBF
sha3_384: c4e885490fb5bcf12acaa035e2abeea421ccc0f0f5516576addf72b0fcaa511d58f9fe4275cd9f645ee7825f46d752b4
ep_bytes: 83ec04c70424902bd3518b042483c404
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qcfh also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.1ccc748805406cd7
McAfeeGenericRXGJ-XY!937A799AB105
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.805406
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qcfh
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.351959A
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.uuZ@aeSC5Sd
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqX/oXwCKA2gyizZUzLePTk)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qcfh?

Trojan.Win32.Copak.qcfh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment