Trojan

Trojan.Win32.Copak.mpyy removal tips

Malware Removal

The Trojan.Win32.Copak.mpyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mpyy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.mpyy?


File Info:

name: 9ABA9E902F6A690BDCFB.mlw
path: /opt/CAPEv2/storage/binaries/9d3375bb5a401a663ca40ca7298e48f51bba8774f6d6ced758d0fac9ba23fa2e
crc32: 6034C9DF
md5: 9aba9e902f6a690bdcfb895a7b928c6b
sha1: 187779a22fd32f8b21e3e0c082db2264eb545d8a
sha256: 9d3375bb5a401a663ca40ca7298e48f51bba8774f6d6ced758d0fac9ba23fa2e
sha512: 8cd9b67ce96a5cf1bbc83e878d92b5e4402967fc34dc09f596abf48c6e4b7eac93a5f3e37d579596742ca0cc7c0caadb0eddb507c9235e1195c86c1442a5e076
ssdeep: 6144:jdGjIa4aljqTXmxKRQSaOggxgwINfxK/WQ73u/TSXmxKRQSaOx:jdGBp+Kx4r35u6/XDONx4r3x
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C64AD15CA850F40DE0E21FF939C06904D75CBD97FAB4DAAA6DFA8300653A5A17CCD8E
sha3_384: 7bf3d27ef31dc516bfc463eb34c1c25ed3b74b297a480258c9ef0e5a480281770ff8aae02bb6ba6f9e576169fe74d9c8
ep_bytes: b8fffb237301d268d8854000688022db
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mpyy also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.899319
FireEyeGeneric.mg.9aba9e902f6a690b
McAfeeGlupteba-FTSD!9ABA9E902F6A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.mpyy
BitDefenderGen:Variant.Razy.899319
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.899319
SophosML/PE-A + Troj/Agent-BGOS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
EmsisoftGen:Variant.Razy.899319 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.899319
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DDB8F7
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.899319
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazoL6na2lrfwx2a9hS2U8pnr)
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.02f6a6

How to remove Trojan.Win32.Copak.mpyy?

Trojan.Win32.Copak.mpyy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment