Trojan

Trojan.Win32.Copak.qbgk removal guide

Malware Removal

The Trojan.Win32.Copak.qbgk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbgk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qbgk?


File Info:

name: DBD7D9889568CF57FD0A.mlw
path: /opt/CAPEv2/storage/binaries/2350fbcb9a3551bbb5525e55c77c3d6992df611b733458d2203489e74a977f58
crc32: 7660F988
md5: dbd7d9889568cf57fd0a75485b2e2062
sha1: 4a51e0e30f751ac57b8403d2984bbc638aebb3e7
sha256: 2350fbcb9a3551bbb5525e55c77c3d6992df611b733458d2203489e74a977f58
sha512: 65ca753044a7bcc38e220e96b6380ca5397c528d6f098863c9a9dd74b7042ec679034c817fc8e3df0890110dcfdfb6c1f3b65e43709a9d0353f92a62c4df2070
ssdeep: 1536:gRCs4wGM+S7VoYl0fv48PvRK6OwIYjXirzLWZHxVhfh1LAkDWlSRiC9HX:mCi/6Y0vZKVoQzL4HHj1LDWURiYX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T179A3CFA0FFCD356FE8D89F733DC2506814DA606198B7305A8B6D24A1C4D21F536F6A3A
sha3_384: 89dc908d869a215ebf9ccd832d78efb47578fc8601ec8f3c62fb1aeb435e83ee35abafe8c031ddbd3acfa13924e4daff
ep_bytes: 83ec04c704242520dfa15e83ec04c704
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbgk also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.dbd7d9889568cf57
CAT-QuickHealTrojan.Glupteba
McAfeeArtemis!DBD7D9889568
MalwarebytesTrojan.Crypt
ZillyaTrojan.Injector.Win32.1478490
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.guY@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9932972-0
KasperskyTrojan.Win32.Copak.qbgk
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazqMTplEn0+VsCp+tZuwh1Ac)
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.nc
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.335238E
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ArcabitTrojan.Razy.DD3501
ZoneAlarmTrojan.Win32.Copak.qbgk
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
CylanceUnsafe
TencentTrojan.Win32.Copak.wd
IkarusTrojan.Win32.Glupteba
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.89568c
AvastWin32:Trojan-gen

How to remove Trojan.Win32.Copak.qbgk?

Trojan.Win32.Copak.qbgk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment