Trojan

How to remove “Trojan.Win32.Copak.qeiu”?

Malware Removal

The Trojan.Win32.Copak.qeiu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qeiu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qeiu?


File Info:

name: 56E7446BB5ADB7275D7E.mlw
path: /opt/CAPEv2/storage/binaries/37176915bb39ec4da7eba3a640455a416a02c48c8a9cd4402c170479d0a82b6d
crc32: 82BBD93A
md5: 56e7446bb5adb7275d7ea2b7657b487a
sha1: 3f752a4641a3fdb4eca2ba8447b3def8eeda3c3a
sha256: 37176915bb39ec4da7eba3a640455a416a02c48c8a9cd4402c170479d0a82b6d
sha512: a6ac2c7c19b794bb9b476a78f972bdc91ddeadb6943167a0b47eca61e992b66fccc63935a1f3dd7c4237d6470b38fecb853f17830dc3798ae32c86fa760ea58b
ssdeep: 3072:ZVBUcNKWtZUVI3fs7ZTfRUXJFJTKAb7HwWIPTcryCiZBu1a2TgI42sYLVPk7Z6je:ZjZNKWtOVIfs7lfRuF7wjPTce3ZBu1P6
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BAF3E0D8707E2E17F52F58F05B810DB62CED4FD3E915B4AADBB9686CA1D002F3848865
sha3_384: 0104ddae004ebe5549211dbe8edcc2dd19cdd75418a7559baed710191213a9bc156643d33017e555402fb39b8983a7f8
ep_bytes: 6839c1b69f8b042483c4044289d783ec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qeiu also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
McAfeeArtemis!56E7446BB5AD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Glupteba.0ca92181
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaGen:NN.ZexaF.34212.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB922
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qeiu
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB922
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SentinelOneStatic AI – Malicious PE
FireEyeGeneric.mg.56e7446bb5adb727
SophosMal/Generic-R + Troj/Agent-BGOS
APEXMalicious
GDataGen:Variant.Razy.900994
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34E7416
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (CLOUD)
eGambitUnsafe.AI_Score_96%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.bb5adb
PandaTrj/CI.A

How to remove Trojan.Win32.Copak.qeiu?

Trojan.Win32.Copak.qeiu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment