Trojan

How to remove “Trojan.Win32.Copak.rgiz”?

Malware Removal

The Trojan.Win32.Copak.rgiz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rgiz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rgiz?


File Info:

name: 0BFC6BD5F8B958A5EECB.mlw
path: /opt/CAPEv2/storage/binaries/aa1433a20b978f847f80a1d9ce45e9108d960d811983e9f165229a47fd4cca4d
crc32: 0ADD74DA
md5: 0bfc6bd5f8b958a5eecba2d66fe8f1db
sha1: e3f3fe1e331ca68cb1eed382a8b1e0c1479c63e7
sha256: aa1433a20b978f847f80a1d9ce45e9108d960d811983e9f165229a47fd4cca4d
sha512: 2da258caf93db587eb6206ece179d1635a5ba5d76aba42b7f4496cc094daf358cc187aff0d188ec5e16bb053054701d140d4e005ab70b062c73defbc244e4534
ssdeep: 3072:POQdA7g+GK/f9Bbd4M5baUM/pRY6lY+lBbd4M5vu8GISBWacdBg9NBbd4M5baUMS:POQdAs+GK/fzQXEQgQSAroDQXEQQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T115841204A3415ED4E9B026F712A36FC93609F0F4B28D9703DA248EF8AB05695F8D9B57
sha3_384: 0486d823733246c77ff495cab9cbea6d6082c5ef326f86a9fa57e8af9742d350a73b241f95f1663e8162338d11296ad4
ep_bytes: bf0000000083ec0489042409f168675f
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rgiz also known as:

LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
DrWebTrojan.Packed2.43250
MicroWorld-eScanTrojan.GenericKD.46124967
FireEyeGeneric.mg.0bfc6bd5f8b958a5
ALYacTrojan.GenericKD.46124967
CylanceUnsafe
VIPRETrojan.GenericKD.46124967
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Copak.af6a21ee
K7GWTrojan ( 0058c5ff1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34606.xmZ@aqxLbnk
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
ClamAVWin.Packed.Copak-9853643-0
KasperskyTrojan.Win32.Copak.rgiz
BitDefenderTrojan.GenericKD.46124967
NANO-AntivirusTrojan.Win32.Agent.ixszcw
AvastWin32:Evo-gen [Susp]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareTrojan.GenericKD.46124967
EmsisoftTrojan.GenericKD.46124967 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Patched.Ren.Gen
TrendMicroTROJ_GEN.R03BC0DHH22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
SophosML/PE-A + Troj/Agent-BGZJ
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.46124967 (2x)
JiangminTrojan.Copak.civ
GoogleDetected
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Tampering.s
ArcabitTrojan.Generic.D2BFCFA7
ZoneAlarmTrojan.Win32.Copak.rgiz
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369371
Acronissuspicious
McAfeeGenericRXAA-FA!0BFC6BD5F8B9
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R03BC0DHH22
TencentTrojan.Win32.Copak.hb
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.e331ca
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Copak.rgiz?

Trojan.Win32.Copak.rgiz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment