Trojan

About “Trojan.Win32.Copak.qctd” infection

Malware Removal

The Trojan.Win32.Copak.qctd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qctd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qctd?


File Info:

name: 7ED99C17357DE1ED1E16.mlw
path: /opt/CAPEv2/storage/binaries/05c0e4c2e4bcb36230562940a90208917a5a95b21db415fb4b0ed1a30735e437
crc32: DAB526D3
md5: 7ed99c17357de1ed1e16242ff87339b7
sha1: d2e0f196feb00e5b267203282b696b69b3cb893b
sha256: 05c0e4c2e4bcb36230562940a90208917a5a95b21db415fb4b0ed1a30735e437
sha512: 3d05abb3a193d17f92c428c174c4833d96802a3ad8fb7511e6cacced7460ba432301974795a1b06ade63b891797a4a111a940aec4aabf89cc4ddeb9cdd8d472a
ssdeep: 12288:U4h95T8r9VrL2p4Emi7uQqVFg9r9VrL2p4Eb:1950VrL9Ni7cuVrL9s
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17D84CF65457E8052F0ADED34B680997FA4A42BA2EDC1A93BC75002D3E7133367F93C29
sha3_384: 9567761b75480d9397ffd25e01297a93ba96371186db3fba193e33d0aabb3ad02dbbdc334c7c6b5c510317d8d77d01f2
ep_bytes: 68b04597e55e68d885400029c783ec04
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qctd also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.7ed99c17357de1ed
McAfeeArtemis!7ED99C17357D
MalwarebytesTrojan.Crypt
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.4a7ed488
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7357de
BitDefenderThetaGen:NN.ZexaF.34182.yuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB322
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.qctd
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
SophosTroj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DB322
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
EmsisoftGen:Variant.Razy.865537 (B)
IkarusTrojan.Win32.Glupteba
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33078B8
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qctd
GDataGen:Variant.Razy.865537
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
CylanceUnsafe
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Injector!s9lFQYD97uc
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qctd?

Trojan.Win32.Copak.qctd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment