Trojan

Trojan:Win32/C2Lop!D information

Malware Removal

The Trojan:Win32/C2Lop!D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/C2Lop!D virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
upd.host-domain-lookup.com

How to determine Trojan:Win32/C2Lop!D?


File Info:

crc32: 4A8092E4
md5: c00330673fd92d25a2a348a91c2fb698
name: C00330673FD92D25A2A348A91C2FB698.mlw
sha1: 795f202cc564c0e2e8557d0e0af21eb08c2401c6
sha256: ddf22ca3ef98e417765fcb567cad2263ffb501d0dd94e09950700a21678913d0
sha512: ade07ec3e84e4fa51ae1ec5d80b78684d364a30a5f4658f6bcd510db883f21630538277bcc289d78b92fca7784d2a1a3c057639afd8d7ec17b2a20ba946732f9
ssdeep: 6144:j7ya594YWn53M/usS/5AEMBVtczaTisRvHEO:jO8FWntMvSmKaTTvE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Iendiwod netcoht ren ohohapn.
InternalName: Whosr
FileVersion: 7.6.6.3
CompanyName: Trahhdcg
ProductName: Ttoegl hnobfpae
ProductVersion: 7.6.6.3
FileDescription: Amttdet nissh ele shb
OriginalFilename: Whosr.exe
Translation: 0x0409 0x0409

Trojan:Win32/C2Lop!D also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Swizzor.based
MicroWorld-eScanTrojan.Swizzor.Gen.2
Qihoo-360Win32/Trojan.991
McAfeeSwizzor.gen.a
CylanceUnsafe
VIPRETrojan.Win32.Swizzor.Gen (v)
AegisLabTrojan.Win32.Swizzor.4!c
SangforMalware
K7AntiVirusTrojan ( f10003011 )
BitDefenderTrojan.Swizzor.Gen.2
K7GWTrojan ( f10003011 )
Cybereasonmalicious.73fd92
BitDefenderThetaAI:Packer.A64C013920
CyrenW32/Swizzor-based.2!Maximus
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallMal_Swizzor
AvastWin32:Swizzor
KasperskyTrojan.Win32.Swizzor.b
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareTrojan.Swizzor.Gen.2
SophosML/PE-A + Mal/Swizzor-K
ComodoTrojWare.Win32.TrojanDownloader.Swizzor.Gen@1fy3o0
F-SecureTrojan.TR/Dldr.Swizzor.Gen
ZillyaTrojan.Swizzor.Win32.207845
TrendMicroMal_Swizzor
McAfee-GW-EditionBehavesLike.Win32.Swizzor.fc
FireEyeGeneric.mg.c00330673fd92d25
EmsisoftTrojan.Swizzor.Gen.2 (B)
IkarusTrojan.Win32.Obfuscated
JiangminTrojan/Obfuscated.Gen
AviraTR/Dldr.Swizzor.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Swizzor
MicrosoftTrojan:Win32/C2Lop.gen!D
ArcabitTrojan.Swizzor.Gen.2
ZoneAlarmTrojan.Win32.Swizzor.b
GDataTrojan.Swizzor.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Swizzor.Gen
Acronissuspicious
VBA32Trojan.Win32.Drivecurb.3
ALYacTrojan.Swizzor.Gen.2
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Swizzor.gen
APEXMalicious
ESET-NOD32a variant of Win32/TrojanDownloader.Swizzor.NDI
RisingTrojan.Win32.Swizzor.ul (CLOUD)
YandexTrojan.Swizzor.Gen!Pac.6
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Swizzor.fam!tr
AVGWin32:Swizzor
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/C2Lop!D?

Trojan:Win32/C2Lop!D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment