Trojan

Should I remove “Trojan.Win32.Copak.qbfu”?

Malware Removal

The Trojan.Win32.Copak.qbfu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbfu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.qbfu?


File Info:

name: 020086BF071664CC184A.mlw
path: /opt/CAPEv2/storage/binaries/61482686b90e2277606f0a3f04fe6d7e832053e6607d075f004f4be96741cc31
crc32: 27F943DE
md5: 020086bf071664cc184a84a046a7900e
sha1: e6a6bfe483fb5789e593b8380ece3d7bc4f16c56
sha256: 61482686b90e2277606f0a3f04fe6d7e832053e6607d075f004f4be96741cc31
sha512: f4af6ce2ca8379b3d9c85f9f55b9f1fa5d612c4cd50c814f07c8532ffa20ac5830027ede3f1ce65791faff890c0a3958283a4ec6739d2dc7e7578739dc1dcba1
ssdeep: 6144:fFebCVrf2/BhNQU8ezszbSrKUdb8V5DSbSCU3vRTIpG:08reZnQU1zszbSOyQUQvRUpG
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10644F1CAB83F8E1AEEF85A71D2511904747A59EE9F69AD3584CF4D21CD403D87E03A83
sha3_384: c96bd89740ae11542bb661afd9a946d4067dc3dd69e2e4cb47612682dc5da5cb65efa72c41789f5af1a5751dc752fb74
ep_bytes: b991a3366268d885400009f868001040
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbfu also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.020086bf071664cc
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Ibbgt-9937785-0
KasperskyTrojan.Win32.Copak.qbfu
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazonf0r+XVOBc7Q9/5vUcvO5)
Ad-AwareGen:Variant.Razy.870640
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
ZillyaTrojan.Injector.Win32.1472001
McAfee-GW-EditionBehavesLike.Win32.Glupteba.dc
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.870640
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DD48F0
ZoneAlarmTrojan.Win32.Copak.qbfu
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!020086BF0716
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
PandaTrj/CI.A
TencentTrojan.Win32.Copak.wc
YandexTrojan.Copak!2VTh+v40DJE
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
BitDefenderThetaGen:NN.ZexaF.34212.ruZ@aSwc1te
AVGWin32:Trojan-gen
Cybereasonmalicious.f07166

How to remove Trojan.Win32.Copak.qbfu?

Trojan.Win32.Copak.qbfu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment