Trojan

What is “Trojan.Win32.Copak.mdmz”?

Malware Removal

The Trojan.Win32.Copak.mdmz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mdmz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.mdmz?


File Info:

name: 9DD3CE52B7A61B4993B8.mlw
path: /opt/CAPEv2/storage/binaries/eaf5533e51d1d6f6f0368e7ae9b6c66c50c10862b0d0ceb4873afba6a60b3a4d
crc32: C7B775A7
md5: 9dd3ce52b7a61b4993b883874255a886
sha1: c5cd70c2b3752abf82516c2899264735d36279b7
sha256: eaf5533e51d1d6f6f0368e7ae9b6c66c50c10862b0d0ceb4873afba6a60b3a4d
sha512: 584f61dbeec5ed8328c9dcb67249e9f7b433c37e655dc871972b08c0c8e7a73d1c56e70983f86f2fb3f6f100c711c1b3de6d3c411a8c640a7302f68e59e76ede
ssdeep: 3072:13ZnudLH4QgzejwhfECkm7c0qKdLmYvG6N5qS9qTHInpaxng3dtzemho403Vx:1cdLH4BSsjkm7c0qoLmYOkqTcQVg3dti
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T121F3E09D7F5340D6D7F54D39E685B68E2BFA09EEE1569C76E3C68D0AF88DCA40000A34
sha3_384: 153fa48ec1112302a9693732b9934480687fdd8405a672aef697c163d5f1a5367bbd6475f5b31fc6a63caea4f11f174c
ep_bytes: ba7c9e3c1281efac04581321f168d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mdmz also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
CynetMalicious (score: 100)
FireEyeGeneric.mg.9dd3ce52b7a61b49
McAfeeGenericRXGJ-XZ!ECF62B8172F4
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.2b7a61
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.mdmz
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.333F2C8
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=81)
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Kryptik!1.D284 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.mdmz?

Trojan.Win32.Copak.mdmz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment