Trojan

Trojan.Win32.Copak.mcgi removal guide

Malware Removal

The Trojan.Win32.Copak.mcgi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mcgi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.mcgi?


File Info:

name: 2238B16256BF7A8F351C.mlw
path: /opt/CAPEv2/storage/binaries/27744eabbb67871f0470fd83502f1da760051d95749fc619b5e09aaf79d1c1f4
crc32: 40F4DB3B
md5: 2238b16256bf7a8f351c37188587be37
sha1: 5aac91c032acf4c5abd8d4b243876f31d9e74bb0
sha256: 27744eabbb67871f0470fd83502f1da760051d95749fc619b5e09aaf79d1c1f4
sha512: a0b92d3dc4cfcbfd9778c5f63cb429b60caf8b54b391304b1e5aa1e7bd566290df8649e304b6756cb553538157fa43c63c73e4011f9f74ec812a7e88fca9440d
ssdeep: 6144:zCrPIQ50eS7s6NBxq8R16jF5kdyD5Tx4Vnrb:mDnH6N/q8RkHkdy1TQrb
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1051401B320772053ED3CF2BC81A0953825D73DB4EEC1A479578953842DF1BD9ABA62E4
sha3_384: 8c059a1d795b482e496dd332f5e4fcc6a181498af8d5d53aadeb0ae288d0a3bbb843fe7bc4ecaf006e4677dbb9146b89
ep_bytes: 68257010385a68d885400001ff81c349
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mcgi also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Injuke.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2238b16256bf7a8f
McAfeeArtemis!2238B16256BF
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.e32bf103
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.256bf7
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.mcgi
BitDefenderGen:Trojan.Heur.muW@IPhSZ5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.muW@IPhSZ5
AvastWin32:Trojan-gen
TencentWin32.Trojan.Heur.Hnuu
Ad-AwareGen:Trojan.Heur.muW@IPhSZ5
EmsisoftGen:Trojan.Heur.muW@IPhSZ5 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA622
McAfee-GW-EditionBehavesLike.Win32.RAHack.dc
SophosTroj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.muW@IPhSZ5
AviraTR/Crypt.XPACK.Gen
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Heur.ED862E
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
BitDefenderThetaAI:Packer.5309F06F1A
ALYacGen:Trojan.Heur.muW@IPhSZ5
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazqUDAii0whjjAQbYakaS/WG)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.mcgi?

Trojan.Win32.Copak.mcgi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment