Trojan

Should I remove “Trojan.Win32.Copak.qcxi”?

Malware Removal

The Trojan.Win32.Copak.qcxi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qcxi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.qcxi?


File Info:

name: FC5C72A8D0EB1814B130.mlw
path: /opt/CAPEv2/storage/binaries/8b4c48e18a362d084f095b192ee52880c048060a4f59746307e5483f0001a745
crc32: 98B8967F
md5: fc5c72a8d0eb1814b13095c9297ca455
sha1: 09ec123f604f4ae95e3043cc1dd3218a059b5bb4
sha256: 8b4c48e18a362d084f095b192ee52880c048060a4f59746307e5483f0001a745
sha512: eaa4ded8fbbef80fabadfe97ed71a53c21505b15e6ba10ed2b93fe13a56f674a772602250b9035228e1f5ec842ede6f8b399d70398d80479c31af10234ceb52c
ssdeep: 98304:htdXoQgPgQpuMQgPgQHpnKQgPgQpuMQgPgQB:3dXDcw/cTcw/cB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T187E502AD64DD9A1AF7705139C38FBB784226B962D5EDFEF7BE04820C76085DE48004E6
sha3_384: 6eec44ee242359daecbaec01dad85175125a64535c2cf75a99b6a5fd287b519d416f7f1c8fbdf9c0c6c6bb05544dbcd4
ep_bytes: ba1b6eba1b09db09ce68d885400081e9
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qcxi also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.fc5c72a8d0eb1814
ALYacGen:Variant.Razy.870640
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34182.ixZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.qcxi
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqtbX/+ecjmkE++2ePtRGyP)
SophosTroj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.wc
EmsisoftGen:Variant.Razy.870640 (B)
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.351A266
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!FC5C72A8D0EB
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
TencentTrojan.Win32.Copak.wc
YandexTrojan.Copak!2jPXdHWwJig
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.8d0eb1
AvastWin32:Evo-gen [Susp]

How to remove Trojan.Win32.Copak.qcxi?

Trojan.Win32.Copak.qcxi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment