Trojan

Trojan.Win32.Copak.mcce removal instruction

Malware Removal

The Trojan.Win32.Copak.mcce is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mcce virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mcce?


File Info:

name: D9DE98AAE6C40B32C153.mlw
path: /opt/CAPEv2/storage/binaries/c59b823983e5491a798bae2d624768c631f5908af3c339b2c0234a6498cc50df
crc32: D0967C2C
md5: d9de98aae6c40b32c153a15345dd2109
sha1: 876d22162ebba78b8f539fd1f1429194b9ead05c
sha256: c59b823983e5491a798bae2d624768c631f5908af3c339b2c0234a6498cc50df
sha512: e82fb01c20cea66c1f05b03542f6f3c5149637fb5177d40564330410ddfbfa49ce75c4cac7dab89a881a02cc058ed7f581b9e1caed9f6eb334c21ae6d548c6c4
ssdeep: 1536:hNatqz0CSjr68bIPuH47V0U6grVPASYpfifPBdVatc/pPVURq:qtB3SYIPuH476qA5fuZdVvJKRq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CC83C0A37ED59D0FD6B098B023D0A6DB801CEF62DBCC1697659EC93C4040B85B927E6D
sha3_384: db429d578c7b2ec7bfad518fac1f580ac0502f1fa5e7a3b54c40fb2b85606ae4d9cf93f4329544bd497e56d7123987ce
ep_bytes: 68d1d109375868d88540004981c769bf
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mcce also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fuW@IfSC5Sd
FireEyeGeneric.mg.d9de98aae6c40b32
ALYacGen:Trojan.Heur.fuW@IfSC5Sd
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.de3f4aca
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.ae6c40
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Iboz-9876513-0
KasperskyTrojan.Win32.Copak.mcce
BitDefenderGen:Trojan.Heur.fuW@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10ce6741
Ad-AwareGen:Trojan.Heur.fuW@IfSC5Sd
EmsisoftGen:Trojan.Heur.fuW@IfSC5Sd (B)
DrWebTrojan.Siggen13.50230
TrendMicroTROJ_GEN.R002C0DA622
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.fuW@IfSC5Sd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333B024
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!D9DE98AAE6C4
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
RisingTrojan.Injector!1.CD26 (C64:YzY0OlcyPEBZs6nn)
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_96%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaAI:Packer.90472DB81B
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Copak.mcce?

Trojan.Win32.Copak.mcce removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment