Trojan

Trojan:Win32/Glupteba.RPE!MTB malicious file

Malware Removal

The Trojan:Win32/Glupteba.RPE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.RPE!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Glupteba.RPE!MTB?


File Info:

name: 749EAD87E027D1631C7F.mlw
path: /opt/CAPEv2/storage/binaries/9cee8843921f590ab1349f91a3178ede077eb869b28aee789051f071a5e3e393
crc32: AC75AEB1
md5: 749ead87e027d1631c7f54cabca57e9c
sha1: e2853d02a7eabd522a4ccb41e231a454ec2d5ac2
sha256: 9cee8843921f590ab1349f91a3178ede077eb869b28aee789051f071a5e3e393
sha512: ed603ba972542bcc30a5517ac1c7972a6217c2af2264d873c3f05cc77554986d8d189e8ab57949e7f4e3a540ca122f62e6a100399b535cdd079cb2a38f104cd1
ssdeep: 1536:+g2vadwua7DVbKp4sH7QRufZSPzZCMDHNx0UOZ/8HWUAqdd:rbwDDVRAeu4PzZCMDHI5hqL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12983CF16097662ECC1E13C7C86A0EEFC5D6560C31466CE2E7AEAB2D649B9B4C03DD4DC
sha3_384: f5465f1a96f94f33ca2d1fefad2ddf632f6d32350741beb3ce30bc00d18a62fee1a60da94a6d9606c45b23f35a1b3870
ep_bytes: 83ec04c70424000000005f5209f15883
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.RPE!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fuW@IHo3wXi
FireEyeGeneric.mg.749ead87e027d163
ALYacGen:Trojan.Heur.fuW@IHo3wXi
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.115272
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.957e96b3
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.7e027d
BitDefenderThetaAI:Packer.4C54403D1B
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CTNW
TrendMicro-HouseCallTROJ_GEN.R002C0PL521
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Trojan.Heur.fuW@IHo3wXi
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11dc405d
Ad-AwareGen:Trojan.Heur.fuW@IHo3wXi
EmsisoftGen:Trojan.Heur.fuW@IHo3wXi (B)
TrendMicroTROJ_GEN.R002C0PL521
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Crypt
JiangminTrojan.Copak.bgwl
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34E1011
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Glupteba.RPE!MTB
ViRobotTrojan.Win32.Z.Agent.84480.AFR
GDataGen:Trojan.Heur.fuW@IHo3wXi
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGlupteba-FTTQ!749EAD87E027
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLOUD)
YandexTrojan.Copak!w0EEMlrAt6A
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba.RPE!MTB?

Trojan:Win32/Glupteba.RPE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment