Trojan

How to remove “Trojan.Win32.Copak.qdin”?

Malware Removal

The Trojan.Win32.Copak.qdin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdin virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qdin?


File Info:

name: 9D912C07D12BD6A42844.mlw
path: /opt/CAPEv2/storage/binaries/3e98c5bc2fd63c9795f6e9ee6a3037e13d62e03eb5df208069c3cb4a3bce26b3
crc32: 111BA88C
md5: 9d912c07d12bd6a4284448aa19bdfdc4
sha1: 522582ffc1dca2da5e39c8607c68b8ee4ca96515
sha256: 3e98c5bc2fd63c9795f6e9ee6a3037e13d62e03eb5df208069c3cb4a3bce26b3
sha512: f0f0f3a0350a80dd265e26cef73743d6158bf115f42d1cef1cc5a2236cc7a6b7dd20a372fa35879ab99b12ecdd73ef54ebc9d0fc4dd654e55fd787969733b650
ssdeep: 24576:rB6QGm6kGGTyFGm6kGGNEGm6kGGTyFGm6kGN:rP9Pj29PBE9Pj29Pe
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15B25CFCC99059CDED8F62FB4B2DB5993B68DA64186FCF457E904A58C003FD3AC09258B
sha3_384: a3533e2d856300658714489b7a7cd20588b2bdfbe5050ae525b883834440ec348a6be9b6d7b3a64987982359e946460b
ep_bytes: b86178b15881e9206bfb9e4683ec04c7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdin also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.9d912c07d12bd6a4
McAfeeGlupteba-FTSD!9D912C07D12B
MalwarebytesTrojan.Crypt
ZillyaTrojan.Injector.Win32.1472091
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.1a13f034
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7d12bd
BitDefenderThetaGen:NN.ZexaF.34212.avZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qdin
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Razy.900994 (B)
IkarusWin32.Outbreak
GDataGen:Variant.Razy.900994
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33F5855
GridinsoftRansom.Win32.Zbot.sa
ArcabitTrojan.Razy.DDBF82
ZoneAlarmTrojan.Win32.Copak.qdin
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=89)
CylanceUnsafe
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Injector!tEqicCBWNUk
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qdin?

Trojan.Win32.Copak.qdin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment