Trojan

Trojan.Win32.Copak.qdng removal guide

Malware Removal

The Trojan.Win32.Copak.qdng is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdng virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qdng?


File Info:

name: 9FBE9D702F51C86BA6E4.mlw
path: /opt/CAPEv2/storage/binaries/c8065ed5ea61cba222293e8959e1018110a86fb3ac61b9e3eeae81d8c15ad618
crc32: 403918F2
md5: 9fbe9d702f51c86ba6e43cc14ccc598e
sha1: f6e977cc28bf143f39244fcd557b80f7f1df6878
sha256: c8065ed5ea61cba222293e8959e1018110a86fb3ac61b9e3eeae81d8c15ad618
sha512: 70eb8f981732f984a018fbbea3460d3426a11d29f89fd3f5046a247d5b4f6b5a33a3f32762a6301f529388049c95916b73dfb9d4ac0459f0eaacf8d9081e3178
ssdeep: 1536:/3Svo6COEW9FbFX5U2HaebLER0I24KUYgoNwuWlHdXJShlm7RRCt2jlPaAks:/CvoiEW3LHL/Eqz4KgoydXYlmLCt2IAx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19083BE7DFCA04826D4E394FA2F3DB1E6565C1D3F29927979ED50082359850B83E88BF8
sha3_384: a169cc096c84fd04b61914847c8367a1a4908f76099205b14714c6d7b823d1d0a027fb6ee325c1beb07c5a139b93ecca
ep_bytes: 83ec04c704249d71b9155b09fe81c701
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdng also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fuX@IfSC5Sd
FireEyeGeneric.mg.9fbe9d702f51c86b
ALYacGen:Trojan.Heur.fuX@IfSC5Sd
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.ba2aa67b
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qdng
BitDefenderGen:Trojan.Heur.fuX@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Trojan.Heur.fuX@IfSC5Sd
SophosMal/Generic-S + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.RAHack.mc
EmsisoftGen:Trojan.Heur.fuX@IfSC5Sd (B)
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.fuX@IfSC5Sd
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34F7B22
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!9FBE9D702F51
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaAI:Packer.4FFEE2691B
AVGWin32:Trojan-gen
Cybereasonmalicious.02f51c
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.qdng?

Trojan.Win32.Copak.qdng removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment