Trojan

Trojan.Win32.Copak.ntgx malicious file

Malware Removal

The Trojan.Win32.Copak.ntgx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.ntgx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.ntgx?


File Info:

name: 0B8FBFADE93354F29C11.mlw
path: /opt/CAPEv2/storage/binaries/bae3750d9091d87d285f5f60d4ced98fc1e2841973ebdbe9810eff597d6d916e
crc32: 1F1BFB9C
md5: 0b8fbfade93354f29c11d63e519c9af1
sha1: fe2c8e344b66d0d395039849cd4c880b69bc7ff3
sha256: bae3750d9091d87d285f5f60d4ced98fc1e2841973ebdbe9810eff597d6d916e
sha512: 3dcc16231fd090c665dc4297be2db557f26f57f254da16976d517521376157ce3cba1cd761303eef82296680cade30b2c8654b7d34576e740f6a29dc7f4ceb18
ssdeep: 3072:39jlNzK2xbCL0MfX+UIkqY+2iF1nmoJN5uhWP14bstrTWJio+a5VgoRQ1C3B2Abu:3PxPHUIkeTmQ5uh+4bAKJfJ4QQ1CRX+r
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F7F3E0CD23D9DC6BD20CD67A9671C8886B9AE10DD0C722EEFB961CD05D84CC9B183576
sha3_384: e8a08d8ae3e5f4de45c5f76eeb0ec072b11defdf434fa47bf7cabaa8f4e958c031499fc673521b37690eb7d9d76fbbda
ep_bytes: 684729291d5f83ec04c70424d8854000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.ntgx also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.0b8fbfade93354f2
McAfeeArtemis!0B8FBFADE933
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.0f5224f9
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.de9335
BitDefenderThetaGen:NN.ZexaF.34160.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Iboz-9918862-0
KasperskyTrojan.Win32.Copak.ntgx
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfc9c6
Ad-AwareGen:Variant.Razy.900994
SophosTroj/Agent-BGOS
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAE22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.900994 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.900994
JiangminTrojan.Copak.agws
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=81)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DAE22
RisingTrojan.Injector!1.CD26 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.ntgx?

Trojan.Win32.Copak.ntgx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment