Trojan

Trojan.Win32.Copak.kzjr (file analysis)

Malware Removal

The Trojan.Win32.Copak.kzjr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kzjr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.kzjr?


File Info:

name: 980B667D3596EBA137AA.mlw
path: /opt/CAPEv2/storage/binaries/7c2b9bb97c2f12610ea6479063b296e279e8928a1f3b22a714775529f8dc23ab
crc32: FD386E2F
md5: 980b667d3596eba137aa7cf84608e407
sha1: 9c874e906197ce017455e5ec77fe53349774bd02
sha256: 7c2b9bb97c2f12610ea6479063b296e279e8928a1f3b22a714775529f8dc23ab
sha512: 18bf871d9b34a2cb9f2c48fcd053bb60521033e2a8802e5b69788f2511bf729df847c3e8b7c09d6d2d8a2284b17cd2bae18c9ce5ec4dcb7924ab4eb3a0011423
ssdeep: 12288:pm8PGWaf2kZwOPJJHopLSYSPcppx+zfnv09EQ+OPJJHopLSYSPU:pwWa+kmke4YSGK09eke4YSM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15D0502F19006FC84DFCA243DC5E2E2A94E38D906AE2356C29ABF6D75855D3E5CF40D82
sha3_384: 22b881714306fa6fdf3e6bb9af23d1a0f61f9ec17eb59dc7251d4802bd8a01f27da19bfcfa2bad4855def5ae970ab301
ep_bytes: b82b19c27421f368d885400009df83ec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kzjr also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.980b667d3596eba1
CAT-QuickHealTrojan.Copak
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.d3596e
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aOhSZ5
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
AvastWin32:Trojan-gen
ClamAVWin.Malware.Razy-9916221-0
KasperskyTrojan.Win32.Copak.kzjr
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.11dde8b2
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosTroj/Agent-BGOS
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.bisn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.33A0C09
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGenericRXGJ-XZ!84254C77DF0E
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
YandexTrojan.Copak!SKl5qXOkys8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.kzjr?

Trojan.Win32.Copak.kzjr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment