Trojan

Should I remove “Trojan.Win32.Copak.qdlr”?

Malware Removal

The Trojan.Win32.Copak.qdlr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdlr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.qdlr?


File Info:

name: D312728559D46E95E0D2.mlw
path: /opt/CAPEv2/storage/binaries/701cfb9dacf11906c726a0f966e5e471c1634199348833ae8c4494cf8b0ad02e
crc32: 8548092A
md5: d312728559d46e95e0d294a21283c68b
sha1: c5036a67f4fce96047af2a0c017a7d49db36f5e4
sha256: 701cfb9dacf11906c726a0f966e5e471c1634199348833ae8c4494cf8b0ad02e
sha512: 164edee22be776d7fd6c2148908c6d8f68fb0241a1691c98cde7d9d41b058e287b5332bf94d44d4b09c26e34e3ca6da46e51617ea212c78a1a54c905477695d9
ssdeep: 12288:d2Z3K8w2Z3nB8S7YIji6vn0uH41/HwaS7YIji6/:j8w2hnBp6ui/Qrh
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19CC4F0D7B142C159D5F8693C2AF41B04B1E70C89A2EF99C27360E941273A73EBE4E179
sha3_384: 0689c52bcd1a9bdc981814eec644cdf512d0c7c346412c2a3728d971ba8346e7d36105e8fcec4014b2409721d91825fb
ep_bytes: b91ff13f5268d885400083ec04c70424
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdlr also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Injuke.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.d312728559d46e95
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.192ba1b2
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.JuZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
Paloaltogeneric.ml
ClamAVWin.Packed.Ibbgt-9936822-0
KasperskyTrojan.Win32.Copak.qdlr
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wb
Ad-AwareGen:Variant.Razy.870640
SophosMal/Generic-R + Troj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Glupteba.hc
EmsisoftGen:Variant.Razy.870640 (B)
IkarusTrojan.Win32.Glupteba
GDataGen:Variant.Razy.870640
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Injector
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD48F0
ZoneAlarmTrojan.Win32.Copak.qdlr
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!D312728559D4
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.559d46
PandaTrj/CI.A

How to remove Trojan.Win32.Copak.qdlr?

Trojan.Win32.Copak.qdlr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment