Trojan

Trojan.Win32.Copak.rtkf removal tips

Malware Removal

The Trojan.Win32.Copak.rtkf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rtkf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.rtkf?


File Info:

name: C6B36E184D9C97AE93AA.mlw
path: /opt/CAPEv2/storage/binaries/7d8ac3709cb646c625b6c71b3c8b868aeb091b0b8dbfbb3055a4ad4f2f509a1f
crc32: 92D625FA
md5: c6b36e184d9c97ae93aae9f47a535733
sha1: 09c8d4cedbdacb2c9a12e0756cc29233b240cb1d
sha256: 7d8ac3709cb646c625b6c71b3c8b868aeb091b0b8dbfbb3055a4ad4f2f509a1f
sha512: ceec07e1a9f180b28d83e154851b58eb1e43591942da0d22e99b0e084b4d4814070da3994d9a18bcc8f7fa203b33ad6fdb4ae8cb9af9d603cde1f2acf40801a1
ssdeep: 49152:1M/sHT0SF3Oh7U8X+UI7i4VLFw2aHtRD/bazR0vKLXZ:1M/sz0+eh7U8X+UI7hVLFwVHtRDzatuM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EBD5E023FA83A137C4EB61F0467FAF71907ECD359F6041C31A9896B1ADA42D116793CA
sha3_384: 5561240e4746744023a7362f7837fca9f6130d9dc87c620190b13ba14215fb91509f60425ce80514965e313510a69bdf
ep_bytes: 60be8923a1d24b09db81c359bf3dde61
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rtkf also known as:

LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.576052
FireEyeGeneric.mg.c6b36e184d9c97ae
ALYacGen:Variant.Razy.576052
MalwarebytesTrojan.Injector.Generic
ZillyaTrojan.Injector.Win32.1640439
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
AlibabaTrojan:Win32/Copak.27376b33
K7GWTrojan ( 0057fe481 )
Cybereasonmalicious.84d9c9
BitDefenderThetaGen:NN.ZexaF.36250.RoZ@aGXXzDe
CyrenW32/Injector.AJF.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.rtkf
BitDefenderGen:Variant.Razy.576052
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Tiggre.ka
SophosMal/Generic-S
VIPREGen:Variant.Razy.576052
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Variant.Razy.576052 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.576052
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Injector
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.D8CA34
ZoneAlarmTrojan.Win32.Copak.rtkf
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R554362
Acronissuspicious
McAfeeGenericRXAA-FA!C6B36E184D9C
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Injector!1.C865 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.rtkf?

Trojan.Win32.Copak.rtkf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment