Trojan

What is “Trojan.Win32.Copak.qcnv”?

Malware Removal

The Trojan.Win32.Copak.qcnv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qcnv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qcnv?


File Info:

name: 82F86A32D6AAE1F2D376.mlw
path: /opt/CAPEv2/storage/binaries/fc7e8dd22ecbe9e627030b8a6410917d48f61ec303497c65664b417caeb7362b
crc32: CD2C1D10
md5: 82f86a32d6aae1f2d37626957017a7a9
sha1: 74e141c0e2428cdb34ffc982844f04a185879763
sha256: fc7e8dd22ecbe9e627030b8a6410917d48f61ec303497c65664b417caeb7362b
sha512: 54818752207aedd49ea3e31d529dcfae873e96176a348c88d5f7adaabc936855567f2d56ea87fac0cdc04c4d9a37aefe073f3c159aa86d098d997b893cafc906
ssdeep: 3072:I6pkdkTNhxMuCeDfpasVg2A+g/zvQ5BSLTy4tPeM+94py7hUdteI/JQa:WdOfJVhsQ5BSLTymXe4py7hU71qa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B9F3D02BC2174995E9338DFC2AC328F2903AD152BE6B68B59BCCE3D277E50901ED1147
sha3_384: 3710aac5b61dbc8519dd4174a8c2e8788ccf8669e477b9c422a5112b95147aae4b40b4fb54db6745ffb862d2f9bbb6d0
ep_bytes: bf4a72e51281c1676fd88721c983ec04
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qcnv also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.82f86a32d6aae1f2
McAfeeGlupteba-FTSD!82F86A32D6AA
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.2d6aae
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qcnv
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazpTP9KAOkNDEHMrPgPzNKt4)
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34F2A35
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.kuZ@aeSC5Sd
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qcnv?

Trojan.Win32.Copak.qcnv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment