Trojan

Should I remove “Trojan.Win32.Copak.qcym”?

Malware Removal

The Trojan.Win32.Copak.qcym is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qcym virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qcym?


File Info:

name: 7132C70784688A4341D1.mlw
path: /opt/CAPEv2/storage/binaries/f0cf0dc8ab89ee7ccfa803cf5adafe5891cb055ec7e4b5f9649731783b66d036
crc32: 72BD31C4
md5: 7132c70784688a4341d1479bd78cd0d4
sha1: 306fcb332b48746711763e76f1d983cd63d2adfd
sha256: f0cf0dc8ab89ee7ccfa803cf5adafe5891cb055ec7e4b5f9649731783b66d036
sha512: 071112a540280e6c71f5a0b42888d44bcc188672701bebcdcf6c1e44ec5fe912e6bdf0da8b08eae96c07170c2ef2ae088ecd7db493ace549957aec709ae42522
ssdeep: 6144:/NRV5dhlJtx1Z9BFpNRV5dhlJtx1Z9BFpNRV5dhl48gEIMwUYcAkosQ048gIMwYu:rhH5EC5ofA1eAPSjYcY14JmR2fA1eAPZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18264D0FC7686149AD4C7E83087C644802E6A8EE5E45A21F6FE51204B780DFD5BE4E72F
sha3_384: f14ee5bd4710756ede75873ddca68a729962e836b716e284c4125fd18e2a789517bec9a23572cafe2072a622ab0aef22
ep_bytes: bea893d510525883ec04c70424d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qcym also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.7132c70784688a43
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.784688
BitDefenderThetaGen:NN.ZexaE.34182.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qcym
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Variant.Razy.865537 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
SophosML/PE-A + Troj/Agent-BGOS
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3502AD8
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XY!A5A5B5B5AB79
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazoNvgdRkekPy+tmY3RaGb90)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qcym?

Trojan.Win32.Copak.qcym removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment