Trojan

Trojan.Win32.Copak.qbpc removal guide

Malware Removal

The Trojan.Win32.Copak.qbpc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbpc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qbpc?


File Info:

name: BED7D11B6DAAE4EE856F.mlw
path: /opt/CAPEv2/storage/binaries/cff1663976b2ee762077ad6f4c02ad878f9307829ab00749a2ed56c044c1dd39
crc32: 836E85D0
md5: bed7d11b6daae4ee856f852e94181942
sha1: 50d6a9c205a76f698fe0b70a9dd938b9cae6c61f
sha256: cff1663976b2ee762077ad6f4c02ad878f9307829ab00749a2ed56c044c1dd39
sha512: 8fd6f3c93f0a839e270752fa10e23a1728ccf4c7d26e524c392c4e4b07601a4376398f84c0a420f9f46038d65a733eb99b2adf4d0df8ba78ada2be689ea84320
ssdeep: 1536:0LwuIEigLxBkBIW09oJwiS8Ick51wzZd0nD80vHL9Q:0LLj/W4oofccwzZ88gHS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DA83CF8E99C7D679D48811FDB3FB8FE84730B1169D1DA8965B118D3DF0A08234EA85F1
sha3_384: 57e9577c62b973fb6ed2334c9efafac1324882f22e83900842c91d3308fd3b9265224e0c9efb32d0c1438f25d24ed12f
ep_bytes: 68997b4d005901d34768d885400009db
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbpc also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bed7d11b6daae4ee
McAfeeArtemis!BED7D11B6DAA
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.06d637ec
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qbpc
BitDefenderGen:Trojan.Heur.fuW@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.fuW@IfSC5Sd
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.wd
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB122
McAfee-GW-EditionBehavesLike.Win32.RAHack.mc
EmsisoftGen:Trojan.Heur.fuW@IfSC5Sd (B)
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34EDED7
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qbpc
GDataGen:Trojan.Heur.fuW@IfSC5Sd
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaAI:Packer.90472DB81B
ALYacGen:Trojan.Heur.fuW@IfSC5Sd
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DB122
RisingTrojan.Kryptik!1.D284 (CLOUD)
YandexTrojan.Copak!ExaVGAnZtq4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.b6daae
PandaTrj/CI.A

How to remove Trojan.Win32.Copak.qbpc?

Trojan.Win32.Copak.qbpc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment