Trojan

How to remove “Trojan.Win32.Copak.pzlq”?

Malware Removal

The Trojan.Win32.Copak.pzlq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.pzlq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.pzlq?


File Info:

name: 486B6E24E47085E47F87.mlw
path: /opt/CAPEv2/storage/binaries/4696e0d770f8917f33f8e3eecfeb5c56a44775036c3c4aa54eaa48f76a817e88
crc32: 740AA8B9
md5: 486b6e24e47085e47f87ec6033d4937a
sha1: 214de50778e13e780793b327adb39e87f23fc543
sha256: 4696e0d770f8917f33f8e3eecfeb5c56a44775036c3c4aa54eaa48f76a817e88
sha512: 3cf08cb8707134fe19593567e38c8527134546df50886849283339162bc4c04c131eb0f7fe1eb0e089be4c75a90ca2a6355ba6386dafc315c78dd42aa6ac25ae
ssdeep: 3072:fP5lcQITLek7hK67GBqTkmWJ4cgxZ4s2IYpqVPvdfhNDaDbI5zvOjKXt2ugR:fP5lnITLfKTqtTcgxZxpZN2D8RvOjKgL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T172F37A0BB8FEC604F55CAB7E0ACC52BD06B9F06FADC61A6AC6059415B491DCD74F80E8
sha3_384: 81bb27e239d50205179111cb561f706986d5b4b53f986450efe7b12da3b2299ea075fd53b381c53bd6767b31c3e7363b
ep_bytes: be62ccc92581e90100000081c02bce02
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.pzlq also known as:

LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
FireEyeGeneric.mg.486b6e24e47085e4
McAfeeArtemis!486B6E24E470
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Glupteba.0dc3c3a2
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.4e4708
BitDefenderThetaGen:NN.ZexaF.34182.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.pzlq
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.900994
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.wd
EmsisoftGen:Variant.Razy.900994 (B)
ZillyaTrojan.Injector.Win32.1469777
TrendMicroTROJ_GEN.R002C0DAT22
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosMal/Generic-S + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.35092B9
MicrosoftTrojan:Win32/Glupteba.DB!MTB
ZoneAlarmTrojan.Win32.Copak.pzlq
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.900994
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DAT22
RisingTrojan.Kryptik!1.D284 (CLOUD)
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.pzlq?

Trojan.Win32.Copak.pzlq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment