Trojan

Trojan.Win32.Copak.mghz removal instruction

Malware Removal

The Trojan.Win32.Copak.mghz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mghz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mghz?


File Info:

name: 3279441E58EEB0A1EB82.mlw
path: /opt/CAPEv2/storage/binaries/177562beb5058ee2f9103ad6325905ae299e8464db6704e74c6c269d66741c81
crc32: 87E83E44
md5: 3279441e58eeb0a1eb82eca6c2739377
sha1: 9d3517cbeb3abf77b6253a738d1774b487b3e373
sha256: 177562beb5058ee2f9103ad6325905ae299e8464db6704e74c6c269d66741c81
sha512: d9075cb64c0f8551d2c73b0ebf2c83bc56807e6aa6d7d6b779cc1109de7a10aa6cea87772b6192a2b67d0753233820e677bf857744b914ceaf2951256529f24f
ssdeep: 1536:NeRHmOu96PmNGUuCPYHSEXcf8rVQh02aTZLdR7BovzUgra0WT:gW9VGQPEXcfoVQh02OZ1ovAYy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E883C00BCF0E160AEF698374B78451006650286AA0CBDBD739F9F74960D6B687D36387
sha3_384: c56451f87c92608203351e44ebb5eb193d425e3e8c01cfce98a526405bc45b6fcee5b4cc6c4ca69cecd551f77fe300b6
ep_bytes: b971e2a27129db81e89922f40968d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mghz also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.3279441e58eeb0a1
McAfeeArtemis!3279441E58EE
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.b015db1d
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Iboz-9933795-0
KasperskyTrojan.Win32.Copak.mghz
BitDefenderGen:Trojan.Heur.fuX@IfSC5Sd
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.Z.Crypt.82945.JI
MicroWorld-eScanGen:Trojan.Heur.fuX@IfSC5Sd
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cfa3b5
Ad-AwareGen:Trojan.Heur.fuX@IfSC5Sd
EmsisoftGen:Trojan.Heur.fuX@IfSC5Sd (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA722
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.fuX@IfSC5Sd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33962EC
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
BitDefenderThetaAI:Packer.4FFEE2691B
ALYacGen:Trojan.Heur.fuX@IfSC5Sd
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA722
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.e58eeb

How to remove Trojan.Win32.Copak.mghz?

Trojan.Win32.Copak.mghz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment