Trojan

Trojan.Win32.Copak.mkfg removal guide

Malware Removal

The Trojan.Win32.Copak.mkfg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mkfg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.mkfg?


File Info:

name: C91571ABCAA07F264021.mlw
path: /opt/CAPEv2/storage/binaries/1414fc7519f3cef5f6f93e72cf684cae97604d6fe0d289d80b3cde344833ab6a
crc32: A25A208B
md5: c91571abcaa07f264021c2622b72e2e7
sha1: b06acd162bdcc7c09864979ad79e8016baac8131
sha256: 1414fc7519f3cef5f6f93e72cf684cae97604d6fe0d289d80b3cde344833ab6a
sha512: 46213aa2774cac4343015187f74993179befb98c29c9e851fca2a93cb8e3033f7728d5226190ebc310036ae2a69b040c076541128c094ede07d1cc45e47bdf8d
ssdeep: 3072:Rv+giqwn8rpYJZad9eTKFX1PchywNioyhIOgSUPb:jiqw8rpwZadfFPcY2yhZgSUPb
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B9F3D08B4E10F412F0BE4FB9818078F43559010EBE6306F7BAB949A477F799DA1A3635
sha3_384: b6498af3081a6fe487d015035ca72d32642da7f016746c25370cd136115ed7a58697020d66d98e40ea5645a49d642447
ep_bytes: b851bab7fc68d885400009f368001040
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mkfg also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c91571abcaa07f26
McAfeeArtemis!C91571ABCAA0
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.e1628a44
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.bcaa07
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DA822
KasperskyTrojan.Win32.Copak.mkfg
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfd9f2
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA822
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosMal/Generic-R + Troj/Agent-BGOS
APEXMalicious
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.boms
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3351CD4
MicrosoftTrojan:Win32/Glupteba.DB!MTB
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.BF57 (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.mkfg?

Trojan.Win32.Copak.mkfg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment