Trojan

Trojan.Win32.Copak.rgyu removal

Malware Removal

The Trojan.Win32.Copak.rgyu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rgyu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rgyu?


File Info:

name: 7F5E0473EF9CA1510060.mlw
path: /opt/CAPEv2/storage/binaries/d813d666ee85c53689d8b3c767222aeaa6ac02a08e08d8743abe63dd1b61786b
crc32: F4081596
md5: 7f5e0473ef9ca151006000aca76b7150
sha1: 740b71833d2e2075cc6e790305c225a44a1b58b2
sha256: d813d666ee85c53689d8b3c767222aeaa6ac02a08e08d8743abe63dd1b61786b
sha512: 55a3d692b2da1524de68a6f71a740a83927cb788049bc9e700f90a4f47ed1e1b47bfdcd0eef077d01f5c09cb978f5500a7d88e9ccf8f14c894ff895c9246fd2d
ssdeep: 3072:DeaiyrAcD/QIBbd4M5baUM/pRY6lY+lBbd4M5vu8GISBWacdBg9NBbd4M5baUM/K:DniWDzQXEQgQSAroDQXEQQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CD840244A3411EE8D9B076F312A36FC97504E0F4B38D9703CA244EEC9B099A5B9D9F5B
sha3_384: 1ffab52a359e10681bd05ff979a3ee20056fa7bb3a4e43f2a9987b78a16c9a70ebde64b5464c32215e4d68ed73f334c7
ep_bytes: bb0000000056b93b96538b21f9415841
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rgyu also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46124967
FireEyeGeneric.mg.7f5e0473ef9ca151
McAfeeGenericRXAA-FA!7F5E0473EF9C
CylanceUnsafe
VIPRETrojan.GenericKD.46124967
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.33d2e2
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
ClamAVWin.Packed.Copak-9853643-0
KasperskyTrojan.Win32.Copak.rgyu
BitDefenderTrojan.GenericKD.46124967
NANO-AntivirusTrojan.Win32.Agent.ixszcw
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.hb
Ad-AwareTrojan.GenericKD.46124967
EmsisoftTrojan.GenericKD.46124967 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
SophosML/PE-A + Troj/Agent-BGZJ
IkarusTrojan.Kryptik
JiangminTrojan.Copak.civ
GoogleDetected
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.C686
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.46124967 (2x)
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369371
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34606.xmZ@aqxLbnk
ALYacTrojan.GenericKD.46124967
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Injector!1.C865 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.rgyu?

Trojan.Win32.Copak.rgyu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment