Trojan

Trojan.Win32.Copak.qchg removal tips

Malware Removal

The Trojan.Win32.Copak.qchg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qchg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qchg?


File Info:

name: 5866AB643D65E2049D2B.mlw
path: /opt/CAPEv2/storage/binaries/11f720fab94f2efcabae9a66c161ce56ef27b22809ff838ad7859460b11ef30b
crc32: 199FF87D
md5: 5866ab643d65e2049d2bcf22ade4f5f0
sha1: 30caf54270272a394f418a263dcb752e54170fbc
sha256: 11f720fab94f2efcabae9a66c161ce56ef27b22809ff838ad7859460b11ef30b
sha512: 43379ad67f095ff0c61a23bb72062fadcb85c0d6badfc7567de66d23f20f2b5beba2d7bf7c4bd686fd8ade95a4c9d72ab6237a81680cf7c83a92f3ad2970f14d
ssdeep: 24576:tBJmlSou9V0c3oQdfA7XUXBeOtsaEbnmG51MiQ8gxYd0ul6VUU/K+Dj4o+S:tnmhutoCyce+sVbmkRDmxVUU/Kav+S
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18B75338E086273B3FF69DF7C816AB90D01754B832C1EC5CB4B61E655ECA62859CEC570
sha3_384: 07b67baecf889ea7ba6f8642ea088a99b7ccb30ecb606b9177e8616f401fd7f45df06e6c147b11c8588b135fb1b8f4f6
ep_bytes: bb0000000083ec0489342450585981c7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qchg also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3686042
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.270272
VirITWin32.NSPacker.A
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qchg
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosML/PE-A + Mal/TibsPak
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPREPacker.NSAnti.Gen (v)
TrendMicroTROJ_GEN.R002C0DB322
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.5866ab643d65e204
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68E
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ZoneAlarmTrojan.Win32.Copak.qchg
GDataWin32.Application.Coinminer.3KDM9O
CynetMalicious (score: 100)
McAfeeGenericRXAA-FA!5866AB643D65
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DB322
RisingTrojan.Kryptik!1.D12D (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34182.InZ@aGh0P9j
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.qchg?

Trojan.Win32.Copak.qchg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment