Trojan

Trojan.Win32.Copak.prco removal tips

Malware Removal

The Trojan.Win32.Copak.prco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.prco virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.prco?


File Info:

name: FE1808F0504C3D1B13CE.mlw
path: /opt/CAPEv2/storage/binaries/43df08aa1e37efaed9a2dca80a495438c963f76cd13e537d8be323bbae0a09e8
crc32: 2CA4A8F2
md5: fe1808f0504c3d1b13ce95019d368e7b
sha1: d5c848ccbcc460c40e8b3be0006659a231cdef62
sha256: 43df08aa1e37efaed9a2dca80a495438c963f76cd13e537d8be323bbae0a09e8
sha512: cca90cc46f29514078ebaa6273a40bc44a6957ca44930fe20a2271c985b7c967abcdc1e24b98a57136f8735a12a8db4f43dfce7c748acc55ec0e7070c214d0cd
ssdeep: 3072:cAEGsibUvRdhK3eWJezxv6QxEAwoQoNzSawsA32WCHUKa7OfMHwqOaQu36Z7TkfL:cAEGJnuWJUjaAKKSdsz5aOawDYAve
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14DF3DF3989268586F5926A3C36897AFB5FCB1F3E0C15821EABB791E4170BF0401DC46F
sha3_384: 73dcbb3daa168527542df61fa03cec018ea47b0d2cd92543f0b219a0c30776babf19f826d0e48af5ea598a948d098054
ep_bytes: 83ec04c704245e2bdb1f5ebbe620116c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.prco also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
CynetMalicious (score: 100)
FireEyeGeneric.mg.fe1808f0504c3d1b
McAfeeArtemis!FE1808F0504C
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.f4153ed2
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.0504c3
BitDefenderThetaGen:NN.ZexaF.34160.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAL22
AvastWin32:Evo-gen [Susp]
KasperskyTrojan.Win32.Copak.prco
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
TencentTrojan.Win32.Copak.wd
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
TrendMicroTROJ_GEN.R002C0DAL22
EmsisoftGen:Variant.Razy.900994 (B)
GDataGen:Variant.Razy.900994
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.33A10C9
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
ALYacGen:Variant.Razy.900994
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Injector!p291vG6Dk7U
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.prco?

Trojan.Win32.Copak.prco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment