Trojan

Should I remove “Trojan.Win32.Copak.kzjg”?

Malware Removal

The Trojan.Win32.Copak.kzjg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kzjg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kzjg?


File Info:

name: F3A24D34BD085B57627B.mlw
path: /opt/CAPEv2/storage/binaries/cbbb3cbb5ebb11df0211f48fd54012e22a6152947e5cb70814c4bd95d46d0743
crc32: D745A1B1
md5: f3a24d34bd085b57627b326c87150f74
sha1: af2c1cddfe985645ac20b2b324a6d83e30d63bf1
sha256: cbbb3cbb5ebb11df0211f48fd54012e22a6152947e5cb70814c4bd95d46d0743
sha512: e4cfa57c9dea05ea93a39bc172d1245941b823758ce6681e433a5af9638cb9dba03b4a4c79586af2d967fb797fa26a5d51526fe30230d6361c85dd3731621262
ssdeep: 3072:Is0uDfjAmHYNPuJDcJ1hVIB0EC3m0804aQ/6rv5v014jFbsR:F0QYI41hVIk3mNamevl014jFbG
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13CF3D037441B7127F525603A7D86C6801ABEED2D3CAEA303AECCD37C6D92725A4C57A1
sha3_384: 7a02d0f13a10704f347a7f9c8b867cb7b7cee3ab54c56cfb576587b7e235d3b84381658542f2ff53189fd3c4350f3f75
ep_bytes: bfa0d3850b68d885400009f021f06800
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kzjg also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.f3a24d34bd085b57
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4bd085
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Malware.Razy-9917524-0
KasperskyTrojan.Win32.Copak.kzjg
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce7674
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
EmsisoftGen:Variant.Razy.900994 (B)
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.biuk
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3333A74
ArcabitTrojan.Razy.DDBF82
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!C2181A520D19
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (CLASSIC)
YandexTrojan.Copak!qWGOEDVIYck
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.kzjg?

Trojan.Win32.Copak.kzjg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment