Trojan

Trojan.Win32.Copak.qbsb malicious file

Malware Removal

The Trojan.Win32.Copak.qbsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbsb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qbsb?


File Info:

name: 9EA43BFAC658B78AF510.mlw
path: /opt/CAPEv2/storage/binaries/d28a69d2ba729d4469adaee953062aca7bdbe968b25ccb08c32c4630ac11ac8d
crc32: D114118E
md5: 9ea43bfac658b78af510492210ed9bef
sha1: fed8fc2b4b15c4d382d02cf34a942f58fcbe84c9
sha256: d28a69d2ba729d4469adaee953062aca7bdbe968b25ccb08c32c4630ac11ac8d
sha512: 0ca833f32efb9d34af19f9cc19ba5f88853638337703d34efda79acc9e32a8422113d046346ba17d1deb028026d442eeb4e8537ecad93aeacd7bae85e140ab19
ssdeep: 12288:EosqNICrDZbl5fAGFajDZblTvRFZJZbl5fAGFajDZblC:EosC1DBl5f9Fa/BlTJJBl5f9Fa/BlC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B8E4DF4DEE341CD0D91466B87BFEB9A0E6A9AFC6415D8D6B4613308B0D80C3D7A64D2F
sha3_384: 1b40648bcc6858912273e6d2703553613923709ba47a71b45a323675dfb46797931b88cd4688d43cedab3a8e782990e5
ep_bytes: be85e2a7f081ef7eaac9d068d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbsb also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.9ea43bfac658b78a
McAfeeGenericRXGJ-XY!D27A3E34BB15
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.ac658b
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.qbsb
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.jc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.350FDED
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.OuZ@aeSC5Sd
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazoa3PC8mmOHGGMZfTPvzm24)
YandexTrojan.Copak!6XwYaB4aS2U
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qbsb?

Trojan.Win32.Copak.qbsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment