Trojan

Trojan.Win32.Copak.qbuc removal guide

Malware Removal

The Trojan.Win32.Copak.qbuc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbuc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.qbuc?


File Info:

name: 8CF79424BE775852BAAE.mlw
path: /opt/CAPEv2/storage/binaries/cc5a337b52f1bee59522186cbb6b67348638571138653ec1425ded23a066ed3c
crc32: 216D0C63
md5: 8cf79424be775852baae7331ae89a77c
sha1: 618293bf7af1e02d1fd889353b84c77c53824dfc
sha256: cc5a337b52f1bee59522186cbb6b67348638571138653ec1425ded23a066ed3c
sha512: 3091a4e579e3125f30455ffe757214c978e8fe256861977b47cba2f406f900f2807155adebfae3f4648b02f7f915299b1c9dded4e92f833a6179a8e15410dea9
ssdeep: 49152:RBChbsu4JEbU19G1ZEbsu4Jhs3kdBbsu4JEbU19G1ZEbsu4Jv:/Wsu8EYXussu8zsu8EYXussu8v
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1837501C5E0CDFD6AE10E28B64989A95A46EC580FFD53DB9EC7348D180D973C76C860E2
sha3_384: 9990a889feace7390e5cd9388cc66be448428e3a505e672d1cab99e83a097792323da0bf8fc41abe4dd460a7b3b44d74
ep_bytes: b8018d3c5eb9423d745c81c73ea1f730
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbuc also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.8cf79424be775852
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforTrojan.Win32.Copak.qbuc
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4be775
BitDefenderThetaGen:NN.ZexaF.34212.KvZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
KasperskyTrojan.Win32.Copak.qbuc
AlibabaTrojan:Win32/Copak.cd0a032b
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Kryptik!1.BF57 (CLOUD)
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Glupteba.tc
SophosMal/Generic-R + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34F490F
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!8CF79424BE77
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
PandaTrj/CI.A
APEXMalicious
TencentTrojan.Win32.Copak.wc
MAXmalware (ai score=82)
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qbuc?

Trojan.Win32.Copak.qbuc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment