It is common for malware to use names that mimic legitimate software with a slight spelling change (e.g., "qobalt" instead of "cobalt").
Check for registry entries in HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce . Malware often uses these to persist after a reboot. qobalt.exe
Submit the file to VirusTotal to see if other security engines flag it as malicious. Quakbot Strikes with QuakNightmare Exploitation - Cynet It is common for malware to use names