Trojan

UDS:Trojan.Win32.Copak.qdhw removal tips

Malware Removal

The UDS:Trojan.Win32.Copak.qdhw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Copak.qdhw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine UDS:Trojan.Win32.Copak.qdhw?


File Info:

name: 2CB8B9F6D4337DE9B27B.mlw
path: /opt/CAPEv2/storage/binaries/8ea2b6c943398336dc48e665c60589faa927c06e33a1dde2bb09c2b5f74e34af
crc32: 273AA998
md5: 2cb8b9f6d4337de9b27be77cc5c91ec5
sha1: de566874793d3c2cf7f97f01ab88668b0b0efab7
sha256: 8ea2b6c943398336dc48e665c60589faa927c06e33a1dde2bb09c2b5f74e34af
sha512: 100d6adffef139bb769af8ef02e0335ba622345e89b7327084ac19c630c5a812dcd0b020994cbb4b18cd165c197707315607f7f8c0bfc4deb49bc2263c2157e8
ssdeep: 3072:6zMA0fq2Q8La2hhhbZksfx0jSnve/93wluudgbaWOepdDILeX5jSnM:nfFQmhbZkEx04m/93Budt+pkY4M
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10014AD311AC96D70F57B25F0224ED3EC4BBC29D346521E6AEE903F4967E5CC42B325A2
sha3_384: 651a9c1ac6434bfc247eb452662554255251f5e96cb1f004d87572140cedde3fb0eecea860bbf4478b1d8741b2243dbe
ep_bytes: b9a5149cb068d885400081ee381687ce
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

UDS:Trojan.Win32.Copak.qdhw also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.9fbf8c89
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.6d4337
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Razy-9933862-0
KasperskyUDS:Trojan.Win32.Copak.qdhw
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
ZillyaTrojan.Copak.Win32.165711
TrendMicroTROJ_GEN.R002C0DB522
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
FireEyeGeneric.mg.2cb8b9f6d4337de9
EmsisoftGen:Variant.Razy.900994 (B)
IkarusTrojan.Win32.Glupteba
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333319C
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!2CB8B9F6D433
MAXmalware (ai score=88)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DB522
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Injector!2MoS4FhDMPk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34182.muZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove UDS:Trojan.Win32.Copak.qdhw?

UDS:Trojan.Win32.Copak.qdhw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment