Trojan

Trojan.Win32.Copak.qdzz removal guide

Malware Removal

The Trojan.Win32.Copak.qdzz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qdzz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.qdzz?


File Info:

name: 58EF8BA4E5EAD09C0D7D.mlw
path: /opt/CAPEv2/storage/binaries/80e7d6d992b292680a4c5cc571169821401074f155bbf6d2927d68ecf75f73e4
crc32: 26918BE2
md5: 58ef8ba4e5ead09c0d7d2363204d581d
sha1: 7463e72122a57384cea91987476b329155d76f66
sha256: 80e7d6d992b292680a4c5cc571169821401074f155bbf6d2927d68ecf75f73e4
sha512: c80911724f070603e92e5a2f1de15893e99ea3b75cae9491452e7c1c343e71459d2f12b984404d50b60be18fcc5ee695af4996c40b8a7dd042f318e76c43ce0d
ssdeep: 3072:Vuby1x4TecdBHEGm6QvexpcXFan/iJtVySrFjZTnmS8MmMUQHAx2:H1x4p/B5CaMFa/8i2dmS8DFx2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1901401CCC8F8A493DC97CDB48A6156C1F2DF11E945D2FBB15D2D222A40DA0AB175783E
sha3_384: 292a6dce2a0022f9c5960afe8981d232d5dca1ee396045422a729275e1fad57bebe8d235528aae82bc2c6f13a40d0cf2
ep_bytes: 83ec04c70424e500e0805968d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qdzz also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Trojan.Heur.muW@ITwc1te
FireEyeGeneric.mg.58ef8ba4e5ead09c
ALYacGen:Trojan.Heur.muW@ITwc1te
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.501fcbf4
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.C46C008F1B
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB822
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qdzz
BitDefenderGen:Trojan.Heur.muW@ITwc1te
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wc
Ad-AwareGen:Trojan.Heur.muW@ITwc1te
SophosMal/Generic-R + Troj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DB822
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Trojan.Heur.muW@ITwc1te (B)
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.muW@ITwc1te
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34EDFA4
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Heur.EDC45A
ZoneAlarmTrojan.Win32.Copak.qdzz
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeRDN/Generic.hbg
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.4e5ead
PandaTrj/CI.A

How to remove Trojan.Win32.Copak.qdzz?

Trojan.Win32.Copak.qdzz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment