Trojan

Trojan.Win32.Copak.pznk malicious file

Malware Removal

The Trojan.Win32.Copak.pznk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.pznk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.pznk?


File Info:

name: 60EF75AC49273300EE0C.mlw
path: /opt/CAPEv2/storage/binaries/5cad6fafe4c197fe19e1308c41999c392ba3d19c279a3db5209c8a61485c6d12
crc32: E462BB76
md5: 60ef75ac49273300ee0c0d5de1c282cb
sha1: a60610cdafe6788c9a32f791933bc37fbe9d2390
sha256: 5cad6fafe4c197fe19e1308c41999c392ba3d19c279a3db5209c8a61485c6d12
sha512: d7b3d788e3a65a92f83f31a6b80015441a8e85362d8bd409445390defc29a44310ec4c30e4cc60b17e389b6696e2cd7c985199cada0b6cfd20e1e2b7e28befcf
ssdeep: 49152:/B9eBlLn4FA2/ZDlLn4FhkPlLn4FA2/ZDlLn4Ff:rU1nAA2BD1nAyP1nAA2BD1nAf
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19775026F6416385FCE7AC538D49181AAE09D2C2EF0B65B4F5E0613393940C7EB9F3968
sha3_384: b84346b8682b31b59b697fb03b188018f8d6c8a81d4f44d677e6dfe16ed8e9efc9e9c1b7f051f48aab4589f873befb30
ep_bytes: 83ec04c70424f44d582a5f01f383ec04
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.pznk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.60ef75ac49273300
ALYacGen:Variant.Razy.870640
CylanceUnsafe
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.c49273
BitDefenderThetaGen:NN.ZexaF.34182.KvZ@aSwc1te
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.pznk
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Copak.wc
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.tc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.870640
MaxSecureTrojan.Malware.121218.susgen
Antiy-AVLTrojan/Generic.ASMalwS.34F5682
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazp5pdSFL1CRUBPdZ8RZbSK0)
YandexTrojan.Copak!ChAdFFpYXg0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_92%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.pznk?

Trojan.Win32.Copak.pznk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment