Trojan

Trojan.Win32.Copak.qbxk information

Malware Removal

The Trojan.Win32.Copak.qbxk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbxk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qbxk?


File Info:

name: 11B7CE87E2D1984F212F.mlw
path: /opt/CAPEv2/storage/binaries/3620358e3251c6ca2854ca2a3799e6b6dfb58a8e32a9cbe5793b28ea2f96d7d7
crc32: 7FA45FD0
md5: 11b7ce87e2d1984f212fba754c032f19
sha1: 05eca22e9e6aaa8b92d8f7e5fa726b8c034d1f09
sha256: 3620358e3251c6ca2854ca2a3799e6b6dfb58a8e32a9cbe5793b28ea2f96d7d7
sha512: ed29eedb2dfc6762d8a37899a9ca6683914d61c6b86f6c064c97d18144c4a7cba2b540e6c7a3462d85c9c26a60e5af85c70662cf9171b3bbe649ff1c56076509
ssdeep: 1536:roRG2Tp6kLqc+nJB5E2PmXiRDYBtXfEtuwywSgkDPBQRflqyNoIPda+E:roR/V6kLDuuwLSVDGgY9E
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11383BF50138FD809F1E56A32310D346015FC3D9A1AAF386A9BE9FC7623AF25CD5A0BC5
sha3_384: af16723a6f726ff06d99b0899d8d802fb5cbcd046087e3e92c7a82825ed8f52bd6149dec095e7113c7c168d9f7ac2143
ep_bytes: b87799617083ec04c70424d885400021
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbxk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Trojan.Heur.fuW@IfSC5Sd
FireEyeGeneric.mg.11b7ce87e2d1984f
ALYacGen:Trojan.Heur.fuW@IfSC5Sd
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Trojan.Heur.fuW@IfSC5Sd
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaAI:Packer.90472DB81B
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.qbxk
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazrfBDJBXoEXpdTweOMUvlmI)
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.RAHack.mc
EmsisoftGen:Trojan.Heur.fuW@IfSC5Sd (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Glupteba
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qbxk
GDataGen:Trojan.Heur.fuW@IfSC5Sd
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!11B7CE87E2D1
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
TencentTrojan.Win32.Copak.wd
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.7e2d19
AvastWin32:Trojan-gen

How to remove Trojan.Win32.Copak.qbxk?

Trojan.Win32.Copak.qbxk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment