Trojan

Trojan.Win32.Copak.qwdj removal

Malware Removal

The Trojan.Win32.Copak.qwdj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qwdj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qwdj?


File Info:

name: BA828CE89AD96F20FCB7.mlw
path: /opt/CAPEv2/storage/binaries/47f6da2ceb7d1e7cbb1748b59b16939ae444d49758e2f49324ec9d7392ac8532
crc32: F0839A09
md5: ba828ce89ad96f20fcb7467ea95ceac8
sha1: 83e325922b2acabfa7fb21264f090ada8856bb68
sha256: 47f6da2ceb7d1e7cbb1748b59b16939ae444d49758e2f49324ec9d7392ac8532
sha512: c420fa3de1da57735896748f56de04d89dfa868d5b0ca6ac6a78678b81d1b8b74b20b47f9ebab874b75f03a5b3572ea98b7ffc9e772ab3b3ad73016bdad4137c
ssdeep: 3072:rjRKNKuXWOmmmZpxJ/O6HgAND6wYBi8PaB28Mp1:JuGOmm0tOggANScE8Mp1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T142C302BEC302AAE2EE401032C36981A593AE694F57A77C3BAFDD641445CDD2B7D46780
sha3_384: 6fc3717a70aa99ca69b7007d295027e90584850d19e2ce674972fec23a77a9619c1dfb89249d4581b08d5ade5f6f9b94
ep_bytes: ba000000005681e9010000005829d950
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qwdj also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.ba828ce89ad96f20
McAfeeGlupteba-FUBP!BA828CE89AD9
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058c5ff1 )
K7AntiVirusTrojan ( 0058c5ff1 )
CyrenW32/Kryptik.ECM.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyTrojan.Win32.Copak.qwdj
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
SophosMal/Generic-R + Troj/Agent-BGOS
DrWebTrojan.Siggen18.6265
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.865537
JiangminWorm.Palevo.dka
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
ArcabitTrojan.Razy.DD3501
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.huY@aejYyMk
ALYacGen:Variant.Razy.865537
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.2566209975
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.22b2ac

How to remove Trojan.Win32.Copak.qwdj?

Trojan.Win32.Copak.qwdj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment