Trojan

Trojan.Win32.Copak.qtie removal guide

Malware Removal

The Trojan.Win32.Copak.qtie is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qtie virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qtie?


File Info:

name: 9FE57A7E8756E53D2DE5.mlw
path: /opt/CAPEv2/storage/binaries/dbb1c633610ac9d2e0f04ec182beb49d6582289d82dd925f5c78273f653d3dcd
crc32: DF7FACC6
md5: 9fe57a7e8756e53d2de5ee52e7cadeb7
sha1: 1d84c060e6a2c8dee23b3425deeba648875391e2
sha256: dbb1c633610ac9d2e0f04ec182beb49d6582289d82dd925f5c78273f653d3dcd
sha512: 849896ed43ac01aa3b9e84d89b61f8757f9d87fc5837796093989aa3ff294339497b9fb904d6ed46ee5f2747138a2a07d5ae93bfbe99fb3c78b335fbfda252f4
ssdeep: 1536:tnxWPIuQyKn75yxVvGTQ6mYR/xCm4arIQeoEx+ODVqe50J1l7Tx:SPIu0ncVvpgRZAoELhqBJ1dx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17F93021C258F2943E641B570FBAE8AC18DBD013772F6788ABFA1755996F0F2824C7A50
sha3_384: 06d710ddfe594638595b8838f3ccabfa7dca96871dbd630a40a6d13fae91ea4b09d9da54191701be87d19c8c92baf771
ep_bytes: ba000000005183ec048934245f5829ff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qtie also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.9fe57a7e8756e53d
McAfeeGlupteba-FUBP!9FE57A7E8756
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005435201 )
K7GWTrojan ( 005435201 )
Cybereasonmalicious.0e6a2c
CyrenW32/Kryptik.ECM.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyTrojan.Win32.Copak.qtie
BitDefenderGen:Variant.Razy.865537
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen17.61038
McAfee-GW-EditionBehavesLike.Win32.Glupteba.nc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ceri
AviraTR/Dropper.Gen
ArcabitTrojan.Razy.DD3501
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R493456
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34712.fuY@aejYyMk
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Dropper
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qtie?

Trojan.Win32.Copak.qtie removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment