Trojan

How to remove “Trojan.Win32.Copak.qdnb”?

Malware Removal

The Trojan.Win32.Copak.qdnb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdnb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qdnb?


File Info:

name: A64CD474E5C647165715.mlw
path: /opt/CAPEv2/storage/binaries/bf0a94abe60c4fda0c434337186ed790c3d11681f01f26a0b2a8c0817a019c7b
crc32: 64676BFE
md5: a64cd474e5c647165715c92a3ff6fd01
sha1: a67abed9fed19a62ff6cf20d49c606f2f0633df3
sha256: bf0a94abe60c4fda0c434337186ed790c3d11681f01f26a0b2a8c0817a019c7b
sha512: fee0a078ddf67f5c31fe352b9ef817a6491658e67d6dfe49ba192b2d2f32e466773f406fdce47cc2d645acaae7d447158c5ef12a2e9b121dada6c213f39b0648
ssdeep: 12288:DQJ2x7LqAbPp51gSS7YIji6vn0uH41/HwaS7YIji6/:Y2pzbPDg6ui/Qrh
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A4C4F1D1475ACC1AE5F871392FB5030AF1EB4189A5EF69C673206A4C2F397349E8E0D9
sha3_384: ec10558e9964d3f6353bc234b33ad189da9df19e9fe1d8bff18aee13817ea45a40fe1ebb1d34c36eb0123f54ee7220cb
ep_bytes: 68d50386815a81c055dbc5ce81e8ad23
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdnb also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.a64cd474e5c64716
McAfeeRDN/Generic.hbg
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.bb6b15f7
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4e5c64
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9916527-0
KasperskyTrojan.Win32.Copak.qdnb
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wb
Ad-AwareGen:Variant.Razy.870640
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.332FA04
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34212.JuZ@aSwc1te
ALYacGen:Variant.Razy.870640
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
RisingTrojan.Injector!1.CD26 (CLOUD)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qdnb?

Trojan.Win32.Copak.qdnb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment