Trojan

Trojan.Win32.Copak.qvgf malicious file

Malware Removal

The Trojan.Win32.Copak.qvgf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qvgf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qvgf?


File Info:

name: 124F47B7E79EEE800407.mlw
path: /opt/CAPEv2/storage/binaries/4091d6e3a061d9424496d94093b215ac7124d9114dcc5d624b9f8e4f1dbba4be
crc32: 96D1C696
md5: 124f47b7e79eee8004070001029561f1
sha1: d5e42bbffe22bee80e9feb53de2682e75723b4ae
sha256: 4091d6e3a061d9424496d94093b215ac7124d9114dcc5d624b9f8e4f1dbba4be
sha512: d77b1416847af58bbe7d90f8ec4f94fddfdb5964d9bf7e04e5b7db2fe688fcab6b55d741bdff52aec414fb39994b262f8c37fd47762ae8603888fda0e6670e5e
ssdeep: 3072:gang1pOe7BME0BxScP50vgxGgT2aoajzQ2zEHcgachUiCCP4D:gang1pT7Bc6cP5bxbzJzchUix4D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A6F312639297E4C5D5A21A30BA431B3A2E3CFC7EE254235DD21DE6860CE6FC93614ED1
sha3_384: cbe3553c004523c26db9cb17e8a666862afd1b0ec27cb33c6565b222399560fe0d194b59895dfc0cca3f26044ae9d85a
ep_bytes: be0000000083ec04891c2409cf29cf5a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qvgf also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.124f47b7e79eee80
McAfeeGlupteba-FUBP!124F47B7E79E
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Kryptik.cc83cd67
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.ffe22b
BitDefenderThetaGen:NN.ZexaF.34712.kuZ@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
TrendMicro-HouseCallTROJ_GEN.R002C0PF922
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9944970-0
KasperskyTrojan.Win32.Copak.qvgf
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
ZillyaTrojan.GenKryptik.Win32.136915
TrendMicroTROJ_GEN.R002C0PF922
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Agent-BGOS
APEXMalicious
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ccsi
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R487408
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=81)
MalwarebytesMalware.AI.4185249204
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qvgf?

Trojan.Win32.Copak.qvgf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment