Trojan

About “Trojan.Win32.Copak.qdny” infection

Malware Removal

The Trojan.Win32.Copak.qdny is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdny virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qdny?


File Info:

name: 8DD0C2E135B51497B584.mlw
path: /opt/CAPEv2/storage/binaries/e5a2dbf8431cd30000d997d9576862a66b9c60c7b8d3d5728438cf164ca54e27
crc32: B29FF628
md5: 8dd0c2e135b51497b584d65b660ffd15
sha1: a6e5c8aaa93d4ded555d90dc1089c4e63ea45106
sha256: e5a2dbf8431cd30000d997d9576862a66b9c60c7b8d3d5728438cf164ca54e27
sha512: ebef2000bcc7c021973daa51b431e35af53fc5523f878192c086c9641445f1fcc5a5bb9edbb66051935c04fc97a8b3d70abd931cee900d7923eefc6206725c57
ssdeep: 3072:t6QNj2M/qg5fJ3VaHE1iw2J6EFUBuFPrTg3UxVKiUHII0Ca3Hcbcf+V:gU5RFak1AnUwf1FOIZCasiK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17DF3E046AD9304E9CE362EB5A9F6ECC18FCD951D79253F3E8C84522F141AC6A00DDA7C
sha3_384: 4ef7d82784aa7aafa23f594289109a5cae95c1fb586007adf3330fe455a11fb3d203b8fc64cce2d144907fff6c75cb57
ep_bytes: ba1dd89e7481ee8a94c86668d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdny also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.8dd0c2e135b51497
McAfeeGlupteba-FTSD!8DD0C2E135B5
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.e835eb0d
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.135b51
BitDefenderThetaGen:NN.ZexaF.34212.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
KasperskyTrojan.Win32.Copak.qdny
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-R + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34DD069
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Kryptik!1.D284 (CLOUD)
MAXmalware (ai score=85)
eGambitUnsafe.AI_Score_79%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.qdny?

Trojan.Win32.Copak.qdny removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment