Trojan

What is “Trojan.Win32.Copak.qdlz”?

Malware Removal

The Trojan.Win32.Copak.qdlz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdlz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk

How to determine Trojan.Win32.Copak.qdlz?


File Info:

name: 9D3C0C0F4936114356E7.mlw
path: /opt/CAPEv2/storage/binaries/82986df476cbc2fc7455700ed2ac3478deb7e6f4256c06a14f80a15cc1110664
crc32: 98EC4367
md5: 9d3c0c0f4936114356e7e5ed2e72899c
sha1: 03f90e2a092bea6754cac1bc342bad411621e74c
sha256: 82986df476cbc2fc7455700ed2ac3478deb7e6f4256c06a14f80a15cc1110664
sha512: 9c31f2607f1ff1598b95628096691537bbcdd6154fd7fc52ce1b6beedf2b4af0b7df3c1e548d8ad02b9e252b3beb8c558068d337c7babe606b60f86b90e664dc
ssdeep: 12288:Oprd+w05ox2B71Np4Ko7jaHAQOI5ox2B71Np4KohhIv55ox2B71Np4Ko7jaHAQOt:ONdSo654zZQHo654zr4Lo654zZQHo65w
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T194D4BE1056FA549DF9D2BB78C7B6337D0369087291D12A7F95E01ED0C22C4E32F9A1E9
sha3_384: 00197a46153935d2e91bd7ae780648688c16635b6d08c0892789039b6ff349a9d57c3c9dbad30aed155c78f784188f12
ep_bytes: b89e55b83c83ec04c70424d885400068
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdlz also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.9d3c0c0f49361143
McAfeeGlupteba-FTSD!9D3C0C0F4936
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.9a340343
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.f49361
BitDefenderThetaGen:NN.ZexaF.34212.OuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9928614-0
KasperskyTrojan.Win32.Copak.qdlz
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.900994
SophosMal/Generic-R + Troj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftGen:Variant.Razy.900994 (B)
IkarusWin32.Outbreak
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qdlz
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qdlz?

Trojan.Win32.Copak.qdlz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment