Trojan

How to remove “Trojan.Win32.Copak.mpbm”?

Malware Removal

The Trojan.Win32.Copak.mpbm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mpbm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mpbm?


File Info:

name: 943F1A42E7EBC094112A.mlw
path: /opt/CAPEv2/storage/binaries/e6e7ce65b92166633627601b1f92ff1b9838cb58d8fd22dbad06ed546db517e3
crc32: 0DAC4EFA
md5: 943f1a42e7ebc094112a4a5db8987d7a
sha1: e5a2e2b235beef62aad0f9bf8dfe8c48156a0270
sha256: e6e7ce65b92166633627601b1f92ff1b9838cb58d8fd22dbad06ed546db517e3
sha512: 3cb627134b87c0d02d111bf6d6405724970f8f2425ba18bc40b0d1e8230a42bb10cd2a769322674ddc12d2a2cab3b9eef4477fe901a4447e9e01c398d0b9049e
ssdeep: 3072:nUDINYnaKUV3NU0mdYCkuUyXcaA9IyVQ/qY/nMLQhAzGvu3mRY8vlhKkchQEO:nKaf7zfCxCY/8mAzeo4KlQB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15EF3DFCAE69E0D05FCB40A39E5C428BA79DE6C53ECD1A4FE2AF5331921D30011D4DA6B
sha3_384: 53a85af8ad78114c24e15800cbbbc6c4eed90a083fb549cde439086f11fd87b038d76a3ee2bc19f746242f201e57ff1a
ep_bytes: ba370bd93868d885400009ff81eb73b7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mpbm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.943f1a42e7ebc094
McAfeeGlupteba-FTSD!943F1A42E7EB
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.2e7ebc
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.mpbm
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazpadtHRS3OB/1IKCSDkwnvT)
Ad-AwareGen:Variant.Razy.900994
SophosMal/Generic-R + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
JiangminTrojan.Copak.brdj
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.332C3C5
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
APEXMalicious
TencentTrojan.Win32.Copak.wa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.mpbm?

Trojan.Win32.Copak.mpbm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment