Trojan

Trojan:Win32/Copak.RF!MTB removal tips

Malware Removal

The Trojan:Win32/Copak.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Copak.RF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Copak.RF!MTB?


File Info:

name: E1C8394811C1E86E4669.mlw
path: /opt/CAPEv2/storage/binaries/9fc6dee48107781b3d93b1260efbffe6e25060ce2b6c98cd9b62d4f34683b34a
crc32: 4AB2CE8C
md5: e1c8394811c1e86e4669eef23d77d7c0
sha1: 27da128afba47d1936a9532406e1d1a16f92e5be
sha256: 9fc6dee48107781b3d93b1260efbffe6e25060ce2b6c98cd9b62d4f34683b34a
sha512: 9225a3ec45c244a4e86698b94e2961f299c8e8f342f08961ce751c83b3da204268f3c8bd522b7482cc612c67ea7324ff1e63335ccca25b66963059ae5284f5d4
ssdeep: 49152:ZhgWeffS2uxmcb2qb0GREL4dX67iLYCQ7TEje0wO:ZhrMf1uxmC2TGREEE7iLYCQ7TEjeVO
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C85F07E25B721CBD8F981B0824D02F3BAA634373753527A58909D220DDEFF19E61E25
sha3_384: 46a0fdbe44b74a89604d63330b5f8a027ef361215be9f077fa6b8d77a9045194929a9a184966aa685e1cc214ead51f71
ep_bytes: 60be8195a8f7b9965461efbf177fd218
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Copak.RF!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
DrWebTrojan.Siggen22.11134
MicroWorld-eScanTrojan.GenericKDZ.103739
FireEyeGeneric.mg.e1c8394811c1e86e
SkyhighBehavesLike.Win32.Generic.tm
McAfeeArtemis!E1C8394811C1
MalwarebytesMalware.AI.369164047
ZillyaTrojan.GenKryptik.Win32.277919
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005ad1751 )
AlibabaTrojan:Win32/Copak.b4eb550d
K7GWTrojan ( 005ad1751 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D1953B
BitDefenderThetaGen:NN.ZexaF.36792.V1W@a4GKaWg
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector_AGen.ADV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Generickdz-10014339-0
KasperskyTrojan.Win32.Copak.akfwo
BitDefenderTrojan.GenericKDZ.103739
NANO-AntivirusTrojan.Win32.GenKryptik.kctmqx
AvastWin32:Evo-gen [Trj]
EmsisoftTrojan.GenericKDZ.103739 (B)
F-SecureTrojan.TR/Injector_AGen.gufrf
VIPRETrojan.GenericKDZ.103739
TrendMicroTROJ_GEN.R002C0DKM23
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cwqg
VaristW32/Copak.F.gen!Eldorado
AviraTR/Injector_AGen.gufrf
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.b.782
MicrosoftTrojan:Win32/Copak.RF!MTB
ZoneAlarmTrojan.Win32.Copak.akfwo
GDataWin32.Trojan.Agent.VZWU6M
GoogleDetected
AhnLab-V3Trojan/Win.Evo-gen.R617285
ALYacTrojan.GenericKDZ.103739
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKM23
RisingTrojan.Injector!1.E280 (CLASSIC)
YandexTrojan.Copak!yIRKFtFJUv4
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Copak.RF!MTB?

Trojan:Win32/Copak.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment