Trojan

Trojan.Win32.Copak.qeje removal guide

Malware Removal

The Trojan.Win32.Copak.qeje is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qeje virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qeje?


File Info:

name: 69EDF9C7B4F66463D0F1.mlw
path: /opt/CAPEv2/storage/binaries/69053da5e333fcceed8a14ff711df0db48d682ed438ce521ba2672facbc92e5b
crc32: 1B9194CC
md5: 69edf9c7b4f66463d0f1699deea4300b
sha1: c05f84af863c6ec7800716cdb7a3982b52c3f332
sha256: 69053da5e333fcceed8a14ff711df0db48d682ed438ce521ba2672facbc92e5b
sha512: 8fdb73330acd37dc3ac00d7a72abc578a3fdb0a8fb4b694200ff7aa7300746b092f35a302e465a69f088171b537ffcec990eeb091500f09e33596ff678e3f728
ssdeep: 12288:4rtksxMnvZbcWRhAcLIObN1t5b0XqiIJvryLjxMnvZbcWRhAcLIObN1t5b0XqiIM:4PCGmWo6ACGTAHWOECGmWo6ACGj
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T136A5CF4C9595B91EEC96F4BD25E2B349AFDF1C03B91E8492C253D8C434A31E162B2E7C
sha3_384: 2474d5badd46d564f982a9c65b51d86b0d98f9be2c5262187ccb5317d96ebfb64b6c995666d7cf490716e988baab1d6a
ep_bytes: 680b9d1a7f5bbf7084c29c68d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qeje also known as:

LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.69edf9c7b4f66463
McAfeeArtemis!69EDF9C7B4F6
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7b4f66
BitDefenderThetaGen:NN.ZexaF.34212.iwZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB922
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-9937757-0
KasperskyTrojan.Win32.Copak.qeje
AlibabaTrojan:Win32/Glupteba.5969ca51
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.865537
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB922
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.865537 (B)
APEXMalicious
AviraHEUR/AGEN.1217036
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.3343795
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qeje
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
ALYacGen:Variant.Razy.865537
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
RisingTrojan.Kryptik!1.D284 (CLOUD)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qeje?

Trojan.Win32.Copak.qeje removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment