Trojan

Trojan.Win32.Copak.qumi removal tips

Malware Removal

The Trojan.Win32.Copak.qumi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qumi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qumi?


File Info:

name: 1D50F68419A4B2C4335A.mlw
path: /opt/CAPEv2/storage/binaries/3d8cc0a00941f4ce200a6fcf2711198caab17584ca9a2cfec765313e1de83214
crc32: FB32419B
md5: 1d50f68419a4b2c4335a1395c1dda8d1
sha1: 07cc992aa0863100501a9ac7b220cfef964f85ba
sha256: 3d8cc0a00941f4ce200a6fcf2711198caab17584ca9a2cfec765313e1de83214
sha512: c19e026f1530dace6a98cd668c7a6d239f24e6ded554756a04d7a4064c4200e5c6b846e3a74dedebd21a038a1a6324cbff88c9f1ead5efb6fba35315f61c26a6
ssdeep: 3072:5mNdYthSeduGnnonLhgT2aoajzQ2zEHcgachUiCCP4D:5mNdYt0GTnnonLhozJzchUix4D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A8F312AE9173F4EACE824D70E4032D737F799A45762A212C964DE9C324C3B49B50AEC5
sha3_384: 81759e95e237342a9872d57b711bb2a70af612fe1448c334bfa3a6cefa8d195128678e10dd47676190886099804a6369
ep_bytes: bf000000005181c30100000089f689f6
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qumi also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.1d50f68419a4b2c4
McAfeeGlupteba-FUBP!1D50F68419A4
MalwarebytesMalware.AI.4185249204
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.aa0863
CyrenW32/Kryptik.ECM.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9944970-0
KasperskyTrojan.Win32.Copak.qumi
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen17.64781
ZillyaTrojan.GenKryptik.Win32.136915
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.865537 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.ccsi
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R487408
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34712.kuZ@aejYyMk
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
CylanceUnsafe
TencentTrojan.Win32.Copak.pa
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qumi?

Trojan.Win32.Copak.qumi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment