Trojan

Trojan.Win32.Copak.rgua removal guide

Malware Removal

The Trojan.Win32.Copak.rgua is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rgua virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rgua?


File Info:

name: 033E667EE071AC9A867F.mlw
path: /opt/CAPEv2/storage/binaries/47c998496a66427736c48d45fdedb7d287a9a42231087cd1754eb4c83554a752
crc32: F0026665
md5: 033e667ee071ac9a867fa1caa1ea72e5
sha1: a28cb1d51b18821ee2ad7e8532a61a759bec2709
sha256: 47c998496a66427736c48d45fdedb7d287a9a42231087cd1754eb4c83554a752
sha512: a1e615ea45f822b00b95f2103dc7047dae46ddacbae4f3687323e2527ceb26b6612c7407850e4362fac19324bd94643221265e197cf8c0f8562ba3eb99407328
ssdeep: 3072:GS3HYZImEpUPHQ1Bbd4M5baUM/pRY6lY+lBbd4M5vu8GISBWacdBg9NBbd4M5baa:GS3HYZxbwbQXEQgQSAroDQXEQQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T185840244A3415EA8D9B476F311A3BFC53508F0F0B29D8B03DB249EF8A7055A5F8D9B1A
sha3_384: 986862876b5801d0695c9928b37e399d0ecc0bde3b7533a5edaf5448361daaa31d92c4e1465e60fc9ca1d0757d8f57ce
ep_bytes: b9000000005689d201d358ba6a9d79d1
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rgua also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.46124967
FireEyeGeneric.mg.033e667ee071ac9a
ALYacTrojan.GenericKD.46124967
MalwarebytesSpyware.PasswordStealer
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderTrojan.GenericKD.46124967
K7GWTrojan ( 0058c5ff1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34646.xmZ@aqxLbnk
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Copak-9853643-0
KasperskyTrojan.Win32.Copak.rgua
AlibabaTrojan:Win32/Copak.c49010cb
NANO-AntivirusTrojan.Win32.Agent.ixszcw
CynetMalicious (score: 100)
ViRobotTrojan.Win32.Z.Agent.376832.DXY
RisingTrojan.Kryptik!1.D238 (CLASSIC)
Ad-AwareTrojan.GenericKD.46124967
SophosML/PE-A + Troj/Agent-BGZJ
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPRETrojan.GenericKD.46124967
TrendMicroTROJ_GEN.R049C0RHH22
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
EmsisoftTrojan.GenericKD.46124967 (B)
IkarusTrojan.Kryptik
JiangminTrojan.Copak.civ
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASBOL.C686
MicrosoftTrojan:Win32/Caynamer.A!ml
GDataTrojan.GenericKD.46124967 (2x)
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R369371
Acronissuspicious
McAfeeGenericRXAA-FA!6820F64616C1
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0RHH22
TencentTrojan.Win32.Copak.hb
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.51b188
AvastWin32:Evo-gen [Trj]

How to remove Trojan.Win32.Copak.rgua?

Trojan.Win32.Copak.rgua removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment