Trojan

Trojan.Win32.Copak.mufe removal guide

Malware Removal

The Trojan.Win32.Copak.mufe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mufe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mufe?


File Info:

name: 5DFAE791B092F93FA7C7.mlw
path: /opt/CAPEv2/storage/binaries/552080b348a973a0a52918a31b58a0055e4147d7b2a3559354c8ecefd67493d0
crc32: 882CD166
md5: 5dfae791b092f93fa7c750b53e517360
sha1: 0be9bd6599cafb0ab72c3b45e98262b27baf6854
sha256: 552080b348a973a0a52918a31b58a0055e4147d7b2a3559354c8ecefd67493d0
sha512: d983a2f56c2af4f551bfe8cf5ac6427fc2dc0cdaf527bd53285a712c7505509001e863089b2fefe343a1131258c9ea3a7203ee3bd0c571dea3119649008d1702
ssdeep: 3072:mhRzpiX4212N8w5nfw2a1h2MV8IC9DjOQ6ix:s9iI2gzfw2uTVTC9OQ6ix
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T190F3DF1508AB5045EC484BB4173ED6FD5FA878617828292BE98FF073BEDA68F3500C76
sha3_384: bab35d665a247097165e0447127f701a81a78b425301a18ab258bcf85c335a05ca943cfe17016b39744e6e97aa22404d
ep_bytes: 68f55fd6708b142483c40481c1746048
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mufe also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.5dfae791b092f93f
McAfeeGenericRXAA-FA!5DFAE791B092
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.7e9ce3d4
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAA22
KasperskyTrojan.Win32.Copak.mufe
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
ZillyaTrojan.Injector.Win32.942803
TrendMicroTROJ_GEN.R002C0DAA22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
JiangminTrojan.Copak.bqkq
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3393FAF
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=88)
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Copak!50flu2H/qfI
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.1b092f

How to remove Trojan.Win32.Copak.mufe?

Trojan.Win32.Copak.mufe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment