Trojan

Trojan.Win32.Copak.qctl removal instruction

Malware Removal

The Trojan.Win32.Copak.qctl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qctl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qctl?


File Info:

name: A3B8CA1E4D95BA49B484.mlw
path: /opt/CAPEv2/storage/binaries/2d2c007113cc187b7337acc34d34eab989e9e3f9da8e7c8c61b056a9011eb1cf
crc32: E8BFAAFD
md5: a3b8ca1e4d95ba49b484e21b191e87fa
sha1: d3bccafba473cdda1bf78e0963a0428b232e95b7
sha256: 2d2c007113cc187b7337acc34d34eab989e9e3f9da8e7c8c61b056a9011eb1cf
sha512: c4f736aee97321e29e84076feb61154586ccfdab43d3a483bf16966e5fcc9f72bbb56bdd5e849e8f44f46b04ba1619a118d10211bb73398add430dcc2f0a443d
ssdeep: 6144:dOivo+PQmYByjIdpuI8R8jTx3+Kh+NDSDD2dpuI8R8jTL:dhoKYBwKZ8R8jT0Kh+YPcZ8R8jTL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13664CFE2E6D8406AE3C16C3D86C1565B3FE63A0E5C86580FB5F54450AE94FCB01E377A
sha3_384: ac77511fae010e0ba5cc93754cd2e677f7d085180204ee91ea524ae50b178e9f0cd3e3ad81f9ceb80615798c68c4942c
ep_bytes: 83ec04c70424d17073c65b09d281c14b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qctl also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.a3b8ca1e4d95ba49
McAfeeGenericRXGJ-XY!A907A80371D7
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1480258
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.e4d95b
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Razy-9937911-0
KasperskyTrojan.Win32.Copak.qctl
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wd
SophosTroj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
EmsisoftGen:Variant.Razy.865537 (B)
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3348B3E
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazq0ODiCS3osHW42O6mQdR24)
YandexTrojan.Copak!M5A0jj3Xsrs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34182.uuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Win32.Copak.qctl?

Trojan.Win32.Copak.qctl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment