Trojan

Trojan.Win32.Copak.mbpu removal guide

Malware Removal

The Trojan.Win32.Copak.mbpu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mbpu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mbpu?


File Info:

name: DCB48E9D3F3E04E94443.mlw
path: /opt/CAPEv2/storage/binaries/701ce5e9eddc9c4f5c85683614cec7ac1f470ed89b8a6e545b6722f6bacc5192
crc32: 6208154B
md5: dcb48e9d3f3e04e944439f2e9a9c646c
sha1: 81b3e509d1af5bb1d03fc4d0ce0325136f0f44e7
sha256: 701ce5e9eddc9c4f5c85683614cec7ac1f470ed89b8a6e545b6722f6bacc5192
sha512: 653da965105932f2473e8b5aec66132e44b73a0ead23380eee8171b90b2ce892b60e81e7d249891987c2b67cffba23cee1a30083a87a371e569a9ae8e9fef791
ssdeep: 3072:L4QSmQPzz+N3IOS6MPVnSjiEwgJXZs/8LHbOK+4ZSRSMveMFmvNUJfl:bZQPWN3IOS6MtHDgJpc2HPvMRpv+mfl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T188F3CF7B39C23104E71668B1FDF24CE279AC2B3177692346AF33079A409D54E8F96A1D
sha3_384: 5bde348903904b129b359b6ece3e49e86b6d95878257f7bd0e3a259ee8bbd0084585354e6f0e9d4ea9fbd5cf6672f421
ep_bytes: 83ec04c70424c63aafe48b042483c404
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mbpu also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.dcb48e9d3f3e04e9
ALYacGen:Variant.Razy.865537
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.mbpu
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfdbed
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.335DEE1
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!B25E7EFA79A2
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.d3f3e0

How to remove Trojan.Win32.Copak.mbpu?

Trojan.Win32.Copak.mbpu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment