Trojan

What is “Trojan.Win32.Copak.rgou”?

Malware Removal

The Trojan.Win32.Copak.rgou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rgou virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rgou?


File Info:

name: 8A1E0164B7BE600DF68B.mlw
path: /opt/CAPEv2/storage/binaries/46a41ce23e45a6077eefd6950cbda91f657b8579df3f527c55fb674edd5db9e9
crc32: 00F0721B
md5: 8a1e0164b7be600df68b4f48ec0261de
sha1: a99e9c4bd58410f693614d524b2f6f40eddbc560
sha256: 46a41ce23e45a6077eefd6950cbda91f657b8579df3f527c55fb674edd5db9e9
sha512: afb1b7540030099bc25fe736fe3e610d846781ebd87718ec825bd0bdfb41c566068cf53b619df2878c33474a445a3242057bfdb542837bd05922d9f3df4dcdc5
ssdeep: 1536:xcmVQL0eDHzCN45sVrC7WH1Ij2WDJaWCP4C5O0uD2oEMB7Sfmf298/xT0pygvKQ8:xsL0ebON45eS2Qlc4sJuD0MBS+f298/R
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14493F15B87835B53D3F60979C16C22C46A6846EEDBC3C81E6F4A77253831B2C66C0A69
sha3_384: f9f1d98ea1cb2c6518850f59252197f061684348c00f0642aca1d3a2edc62745f4906085cf2bfef9b022a98d6ddbabb9
ep_bytes: bf000000005009ce8b1c2483c404beec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rgou also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Siggen18.35043
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.8a1e0164b7be600d
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005435201 )
K7AntiVirusTrojan ( 005435201 )
BitDefenderThetaGen:NN.ZexaF.34592.fuY@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
ClamAVWin.Packed.Razy-9952473-0
KasperskyTrojan.Win32.Copak.rgou
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
VIPREGen:Variant.Razy.865537
TrendMicroTROJ_GEN.R032C0PHE22
McAfee-GW-EditionBehavesLike.Win32.RAHack.nc
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.cgge
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
MicrosoftBehavior:Win32/QbotMod.A!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R496673
Acronissuspicious
McAfeeGlupteba-FUBP!8A1E0164B7BE
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.2099357978
TrendMicro-HouseCallTROJ_GEN.R032C0PHE22
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.bd5841

How to remove Trojan.Win32.Copak.rgou?

Trojan.Win32.Copak.rgou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment