Trojan

Trojan.Win32.Copak.zfql malicious file

Malware Removal

The Trojan.Win32.Copak.zfql is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.zfql virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.zfql?


File Info:

name: EB00F602D6FDBB6CDF31.mlw
path: /opt/CAPEv2/storage/binaries/a823a00c8c54cd31861450682e5e9fa2d0f816c83ef791fb5765f4240d3d4619
crc32: A894C3C6
md5: eb00f602d6fdbb6cdf31cec80359c849
sha1: 9928ab571ad3a011afbd8a1d3d87f1a01b9cee58
sha256: a823a00c8c54cd31861450682e5e9fa2d0f816c83ef791fb5765f4240d3d4619
sha512: feedb68f15d02e73b005cca6255489fe2ca9e1e69fb5fee9e0b5beb303ac7b421a168d8ef46bfbcbd1ae7bf316af8ad505bfaec812f654a04fd1b2924cc4189e
ssdeep: 12288:jvaMJt1m0xKc9OxaZgPnN5jVDa/ZS4fDy:eMVm0xKfda/ZS4fDy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12815385C936357C3CC35577AAD1D8A21A7D078B827EADEA134A37A57B8E33D0D482930
sha3_384: 1b440593c960fe00681f565905e494c4ba128fb743813bb947e7d87229a71332e6e12060069cc7c19145e94e04c4b3b1
ep_bytes: d6c08f7a86a90bfd8348026c01026ad6
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.zfql also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.98449
McAfeePacked-FJB!EB00F602D6FD
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Kryptik.Win32.2329372
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
AlibabaTrojan:Win32/Glupteba.13fda938
K7GWTrojan ( 005a14d51 )
CyrenW32/Zusy.EM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyTrojan.Win32.Copak.zfql
BitDefenderTrojan.GenericKDZ.98449
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win.Z.Kryptik.926208.BXJ
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gifya
EmsisoftTrojan.GenericKDZ.98449 (B)
F-SecureHeuristic.HEUR/AGEN.1343758
VIPRETrojan.GenericKDZ.98449
TrendMicroTROJ_GEN.R002C0DEK23
McAfee-GW-EditionBehavesLike.Win32.Corrupt.dm
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.eb00f602d6fdbb6c
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1TCDDYM
GoogleDetected
AviraHEUR/AGEN.1343758
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik.GIFY
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D18091
ZoneAlarmTrojan.Win32.Copak.zfql
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OB.C5394211
BitDefenderThetaGen:NN.ZexaF.36196.48W@aaiSldb
ALYacTrojan.GenericKDZ.98449
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEK23
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.zfql?

Trojan.Win32.Copak.zfql removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment