Trojan

How to remove “Trojan.Win32.Copak.qbzm”?

Malware Removal

The Trojan.Win32.Copak.qbzm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbzm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.qbzm?


File Info:

name: 2D17C5BF56DE4CE007E0.mlw
path: /opt/CAPEv2/storage/binaries/cbeff7da907049cd089ec31aed56053eee07310f3836833e38188ae129427c0f
crc32: 2D400519
md5: 2d17c5bf56de4ce007e0bed655fb8884
sha1: f52a4869501063d70af25f56abb5ce3438b12b21
sha256: cbeff7da907049cd089ec31aed56053eee07310f3836833e38188ae129427c0f
sha512: ddf4f1b9d7059dd946de9c938582e8457b7d814a34cc0a720f88ca66146f5bbb2f089ccb962e32c0bad3bef8bfc031b0faa07d46fc613ce213c13b16d7dc5bf4
ssdeep: 12288:LstVFhGhezJdnnZ9Rl39TieYAEhL/W4pdwA/TL:wtVfGgz3Zv59eeYAjywA/TL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AA9402C86D3BDB0AF4C3C87C914075B7AF5606DE0BA52230ABDAA3F165067F0A7557A0
sha3_384: a33d9e67166d604ef065c253c20013728f72fe6d68c745d7d1ea94bb2c33fb44f113d87b00f2d07fa4c860140db4759e
ep_bytes: ba96a348d581c168d8ea4881c7fed96d
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbzm also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.2d17c5bf56de4ce0
McAfeeGlupteba-FTSD!2D17C5BF56DE
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1479974
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.7aad6306
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.f56de4
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.qbzm
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wb
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DB222
McAfee-GW-EditionBehavesLike.Win32.Glupteba.gc
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.350839D
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.qbzm
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DB222
RisingTrojan.Injector!1.CD26 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
BitDefenderThetaGen:NN.ZexaF.34182.zuZ@aSwc1te
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.qbzm?

Trojan.Win32.Copak.qbzm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment