Trojan

What is “Trojan.Win32.Copak.ncif”?

Malware Removal

The Trojan.Win32.Copak.ncif is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ncif virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.ncif?


File Info:

name: 859AC4B658794FECC8E4.mlw
path: /opt/CAPEv2/storage/binaries/ee5e2f8c145a5fb9cc7939e81ba9e8c1c36da2ffb494d48f3e44924a4ebcfa7b
crc32: 0201656F
md5: 859ac4b658794fecc8e4391c39709f53
sha1: a55f4d5ba9f4676db5dc987f2d2dd6a623c2daf0
sha256: ee5e2f8c145a5fb9cc7939e81ba9e8c1c36da2ffb494d48f3e44924a4ebcfa7b
sha512: c4336f991cc32323e136a53e3e9bedd766d4b30c701a7b5a02d8e29b58ce2ffb521bd547136cf8d607b52d2626233513d745f1872a3220259677f7634d776f39
ssdeep: 3072:l17NNSl7tDCAHo/HLX6rwtL9SjiiUXh6AeDa6bjjjT2GAtj4iiy44nR1V8Jd//NS:l1JNSLTHoDKroL9+jUXgDDa6bjjjT2G2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19AF3E00928E64314C4F31E78D2F66CCC91A39E26A1DE664E972E4408FDF13B95B8C6F5
sha3_384: fb5a538f041db331a9c6e9f597fa42cf928c6f755f4b9fe3491748d3630cc8707e7a55f6a520a8d1310511ed9a27d9d1
ep_bytes: bbf3a5777f81e891b3d98368d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ncif also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.859ac4b658794fec
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.658794
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAB22
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.ncif
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAB22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.blqk
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34FA7A1
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!859AC4B65879
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.ncif?

Trojan.Win32.Copak.ncif removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment