Trojan

Trojan.Win32.Copak.mbzj removal guide

Malware Removal

The Trojan.Win32.Copak.mbzj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mbzj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mbzj?


File Info:

name: AB5A8B3C0822FF386599.mlw
path: /opt/CAPEv2/storage/binaries/d61f864c55a94deb188dce7bf19d2374fcaaa3fc1ca7d082964c5ff8bda09035
crc32: B1045E4E
md5: ab5a8b3c0822ff38659929ca3826c3bd
sha1: d39ade6426d5f3f5a9cfe863a0e0ec3c575030eb
sha256: d61f864c55a94deb188dce7bf19d2374fcaaa3fc1ca7d082964c5ff8bda09035
sha512: b2386d690d1476c5317b5bb2458c10fdb5bed2bceaa6e3b1b7392e15ea66451a5184032c503977669dba6c8d19961de16773cebd15f3b136e87fb01d8bc7b15d
ssdeep: 3072:WS9g7HDs1RX2IiPR1YLJX6UcyAolqla4ZkWKMNxEJT10tkJ2kIQz:R9g74RXOLYNRc5oQ2bJh4+2kIQz
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15BF3BDAFD45E5B4AE9019DF1F58D69A01CE97B0BF69F4C1EBA9300B142F7490C0958EC
sha3_384: 901fd777bdacfe97b51808236af5d6a9806752378e8ca5f914d58415ee123fbbce7eb700695553ec59d8102e3dae2b5b
ep_bytes: 83ec04c70424072f3c115901d368d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mbzj also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.ab5a8b3c0822ff38
McAfeeArtemis!AB5A8B3C0822
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.cead1e1f
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.c0822f
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.mbzj
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cfbf78
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
TrendMicroTROJ_GEN.R002C0DA622
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=89)
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazq+Z6T0TUMUlOsukWqoYbGN)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.mbzj?

Trojan.Win32.Copak.mbzj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment