Trojan

Trojan:Win32/Copak.MBKO!MTB removal tips

Malware Removal

The Trojan:Win32/Copak.MBKO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Copak.MBKO!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Copak.MBKO!MTB?


File Info:

name: 5FE056B95E8C1A43B503.mlw
path: /opt/CAPEv2/storage/binaries/658d4c4d5cb01a3656bb9a02f07f10b80d92d423bc9dba5a495c49bfd89f2206
crc32: 4791C770
md5: 5fe056b95e8c1a43b503f4450e891383
sha1: 3f69768cb7a824249fcfde6a182c8efc9825dc96
sha256: 658d4c4d5cb01a3656bb9a02f07f10b80d92d423bc9dba5a495c49bfd89f2206
sha512: 43d7eb402fae718b4a277525a6a845cf6cc6c81ebdeb89e954962064d323cc9f66c6a3b39f058ef791afa1ad017da9f23810def197164ed0752b8507b024dc8d
ssdeep: 98304:r+AW2b/yvl5YBLjU8/cOT0MMHMMM6MMZMMMqo30MMHMMM6MMZMMMqaYMMHMMMvMc:rrW2bQl5CXfQ1/ta5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18776A110E6C0D81EE63B41B88926C5F91D1BED86E8654C0B71DE3E4B7B73783245B92B
sha3_384: ce3ff204b17ca95c87b0df7a176cf60104a4f3322395ffc277b13cfde75a0ddc7dcd604d0e0981d0f6f18efc27246533
ep_bytes: be000000005321c768cef306965821ff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Copak.MBKO!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Razy.4!c
MicroWorld-eScanGen:Variant.Razy.373115
FireEyeGeneric.mg.5fe056b95e8c1a43
SkyhighBehavesLike.Win32.Glupteba.wh
McAfeeGlupteba-FTTQ!5FE056B95E8C
Cylanceunsafe
VIPREGen:Variant.Razy.373115
SangforTrojan.Win32.Agent.Vcqr
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.373115
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.cb7a82
BitDefenderThetaGen:NN.ZexaF.36792.@xZ@a4IFsEh
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.79eb3860
NANO-AntivirusTrojan.Win32.Kryptik.kdclhl
ViRobotTrojan.Win.Z.Razy.7355393.F
RisingTrojan.Kryptik!1.D284 (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.DownLoader46.28889
TrendMicroTROJ_GEN.R002C0PK423
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.373115 (B)
IkarusTrojan.Win32.Themida
MAXmalware (ai score=84)
GoogleDetected
AviraTR/Crypt.EPACK.Gen2
VaristW32/Kryptik.ECA.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Copak.MBKO!MTB
ArcabitTrojan.Razy.D5B17B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.373115
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R299848
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.373115
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK423
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Copak.MBKO!MTB?

Trojan:Win32/Copak.MBKO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment