Trojan

How to remove “Trojan.Win32.Copak.rfyv”?

Malware Removal

The Trojan.Win32.Copak.rfyv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rfyv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rfyv?


File Info:

name: 6F6E2D282AEEA67C8FFF.mlw
path: /opt/CAPEv2/storage/binaries/8d09c7a310f102c78d88205e3137b6571242a8ddd865680a411a0c2e48357afb
crc32: 2488FA16
md5: 6f6e2d282aeea67c8fffd5d9222c3fd1
sha1: 5d528f9030076a9f530eea2307e6e7f192cf6446
sha256: 8d09c7a310f102c78d88205e3137b6571242a8ddd865680a411a0c2e48357afb
sha512: 1b3c259f9e042cf1c9550964923c508bd0d1c361c996588b1c7fb6f09ff05b603c859ee4cb44c980e820ec36961881edd49ecad982c409d0bf00bf4a3b1df6f1
ssdeep: 3072:WwfIXhZblTwnI4pqT2aoajzQ2zEHcgachUiCCP4D:WwfQpMKzJzchUix4D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D1F312230137B189CF453F3A9FE21E7B1BFC992BF118156FE64AC897049AD849678847
sha3_384: 521b4e9b60a0b26e5c2debea3de3e30cca784f743716bb8a61e9dd101d223e544dca17a403c30c7b2caacec9facfaacb
ep_bytes: 83ec04c70424000000005e5101d24281
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rfyv also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.6f6e2d282aeea67c
McAfeeGlupteba-FUBP!6F6E2D282AEE
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.136915
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.030076
BitDefenderThetaGen:NN.ZexaF.34582.kuZ@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9944970-0
KasperskyTrojan.Win32.Copak.rfyv
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
APEXMalicious
RisingTrojan.Injector!1.C865 (CLASSIC)
Ad-AwareGen:Variant.Razy.865537
DrWebTrojan.Siggen14.7509
VIPREGen:Variant.Razy.865537
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.865537 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ccsi
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R487408
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MalwarebytesMalware.AI.4185249204
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.rfyv?

Trojan.Win32.Copak.rfyv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment