Trojan

Trojan.Win32.Copak.mfwm information

Malware Removal

The Trojan.Win32.Copak.mfwm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mfwm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mfwm?


File Info:

name: 0D156F9F56426C04EB3F.mlw
path: /opt/CAPEv2/storage/binaries/5e3c5b494fda9dfdc37a23e465518fa4cbc28525aa4c66fe14fb417807162bc7
crc32: AA21E62E
md5: 0d156f9f56426c04eb3f244b1edd6ebd
sha1: 642a9e57050a012954a0c2bfc8b99b6178d31a9c
sha256: 5e3c5b494fda9dfdc37a23e465518fa4cbc28525aa4c66fe14fb417807162bc7
sha512: f641141d4367d2dbf9559e187fd6450a0f56acb2a69d76022126e32c5d4e9abd3a3cc3e6ab319f7430e486283ff5eb219a533e9c4a9022fc622c2b8a803a688b
ssdeep: 6144:I52JCRRK1bwG+e9nId/hIjv97PKrasCd/hIjv95:I52kmbw6I1hI5Gaj1hI55
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BF64DFF9D487A206C2A4FD7933A3C991B578DF9B22294739D744548D8CE980C8BE05FD
sha3_384: 609ac3b7f3596c7fdc8cecf3c60361aef5765ed623fb5a2f82761d1267cdd08b89a29210fac1bdc33f70047688b653b5
ep_bytes: ba2f383b274389db68d8854000680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mfwm also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.0d156f9f56426c04
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.d4a4718a
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Razy.DDBF82
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.mfwm
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10ce6efc
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAC22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
SophosML/PE-A + Troj/Agent-BGOS
Paloaltogeneric.ml
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.337B719
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!0D156F9F5642
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DAC22
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.f56426

How to remove Trojan.Win32.Copak.mfwm?

Trojan.Win32.Copak.mfwm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment