Trojan

How to remove “Trojan.Win32.Copak.mtzb”?

Malware Removal

The Trojan.Win32.Copak.mtzb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.mtzb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.mtzb?


File Info:

name: CC46B13A14F7BD6B9185.mlw
path: /opt/CAPEv2/storage/binaries/3b476fdcf8da895b7253ad0d3a7df86e0eb943854a468a9fc0806ddcae89271c
crc32: 18CFF6B4
md5: cc46b13a14f7bd6b918521f3abaa1c4e
sha1: fb3afc58bdb364bf625eb101612e4c09a38a2e7a
sha256: 3b476fdcf8da895b7253ad0d3a7df86e0eb943854a468a9fc0806ddcae89271c
sha512: 9c662353494836c56e3ebeb74d0cb54ce6b7521d5d217dda20e50d40230ec027aec2cb023352424e9e98f1103105e32352b6ab81519f3c5277445279230d4d8f
ssdeep: 6144:XqqWWZxV1uUdf0q52SDal9mKJ9rdpQEH52SDal9mKJ9rdpx:r3ZxLu+f0qqlIs95RHqlIs95D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AB64BE54F8BFA5CBDB2459F14C067A2F28B9D586FE985F0A86D7801D96C0C923C13DB8
sha3_384: 3271a231f7cbe7068b587b08fd9afca128b742a007ab23afb37ea681ad71454a5c8bf8f3ee9985c2cc7f039fbffb7a64
ep_bytes: bf46e4a8c229c368d885400029da6800
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.mtzb also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.cc46b13a14f7bd6b
McAfeeGlupteba-FTSD!CC46B13A14F7
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaGen:NN.ZexaF.34114.uuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
AvastWin32:Evo-gen [Susp]
KasperskyTrojan.Win32.Copak.mtzb
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wa
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosML/PE-A + Troj/Agent-BGOS
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.337FBD8
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=88)
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazpDL/FZGLn5k0qhdSsBbE2/)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.a14f7b

How to remove Trojan.Win32.Copak.mtzb?

Trojan.Win32.Copak.mtzb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment