Trojan

Trojan.Win32.Copak.mdbn removal guide

Malware Removal

The Trojan.Win32.Copak.mdbn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mdbn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mdbn?


File Info:

name: D1526CD74FC0E99CFC5E.mlw
path: /opt/CAPEv2/storage/binaries/773d2cd6cd44d2e4c31cc2c7611311a6ed44508a8e7dd83fde9b1c3491191d1b
crc32: D3806159
md5: d1526cd74fc0e99cfc5e03f6cef0b470
sha1: 6096de1acf2019b5ace4522999818a4567a1e6a6
sha256: 773d2cd6cd44d2e4c31cc2c7611311a6ed44508a8e7dd83fde9b1c3491191d1b
sha512: ba045d95c7f7146a98f9ba1412addfdffc4c7b8d4b178c560e83f235c6faa92832e9b7245717d38bd8138e90bac97acc9540b919b23ab3f230f1b150144594c8
ssdeep: 49152:wgFIghAcIg7QIghAcIgOUppIghAcIg7QIghAcIgx:j1AS6AZUpBAS6AI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10B95DF665ADE4DC3C0CD407E7560E3898CAB62B194E47C4B96C9383BE36CDE46D805BE
sha3_384: 9c7f4aeab2a17e44c3e14657f5dc067b49503db7a4607d320ee6ac4bb0535feb480a6d771da0a94e1c4c1e86ffb4a583
ep_bytes: be747f0b65682bbd2a215968d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mdbn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.d1526cd74fc0e99c
McAfeeGlupteba-FTSD!617EC9786807
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Iboz-9936807-0
KasperskyTrojan.Win32.Copak.mdbn
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.865537
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazp8AB0EHHro/LSIVXpy3TZD)
SophosTroj/Agent-BGOS
DrWebTrojan.Siggen14.7487
ZillyaTrojan.Injector.Win32.1480138
McAfee-GW-EditionBehavesLike.Win32.RAHack.tc
EmsisoftGen:Variant.Razy.865537 (B)
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.865537
AhnLab-V3Malware/Win32.RL_Generic.R293305
BitDefenderThetaGen:NN.ZexaF.34182.5vZ@aeSC5Sd
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
YandexTrojan.Copak!/509HCe2cOc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.74fc0e
AvastWin32:Evo-gen [Susp]

How to remove Trojan.Win32.Copak.mdbn?

Trojan.Win32.Copak.mdbn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment