Trojan

Trojan:Win32/Glupteba.RPY!MTB removal guide

Malware Removal

The Trojan:Win32/Glupteba.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.RPY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Glupteba.RPY!MTB?


File Info:

name: C5C6EDD02F12413E27AE.mlw
path: /opt/CAPEv2/storage/binaries/dfbc8c321ed6076bc66240154e015a8931f23d7a401da6005664d96e63c8dca1
crc32: 8BE8F301
md5: c5c6edd02f12413e27ae68ff8fc359ce
sha1: 29d3ea9f85518c0dc49f9b8b548b49c3b0a11646
sha256: dfbc8c321ed6076bc66240154e015a8931f23d7a401da6005664d96e63c8dca1
sha512: 085dbe543d5cca39581b5dddf185f864e73589d41935f6c0a9d95651be8a65731c73c7fcb28d2cae29188e35241df2fda03297d967a53561c369f970c7bbe4df
ssdeep: 6144:U0loXiMZapyyfJS7XBaGuX+K39wd2S+l3RsBIA8s8ii:U0loSIapycS7auYw8lsB3851
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BD246C2FB7451372C28203B33A4F58D6F72E957A336A89E0646D801D1367E2983BB7D5
sha3_384: 7f0dfbc77868732c075fe81fa106032cfb4711886cff1f1f87872fe197ec0d5e115db7c3273cd103c3a069515fa4f31c
ep_bytes: b90000000057b85121bbec405b09c281
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.RPY!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.104367
SkyhighBehavesLike.Win32.Ctsinf.dh
McAfeeGlupteba-FUBP!C5C6EDD02F12
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005304e81 )
K7GWTrojan ( 005304e81 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D197AF
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTAQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderTrojan.GenericKDZ.104367
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen24.23664
VIPRETrojan.GenericKDZ.104367
TrendMicroTROJ_GEN.R03BC0PAK24
EmsisoftTrojan.GenericKDZ.104367 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.cwnx
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba.RPY!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataTrojan.GenericKDZ.104367
VaristW32/Kryptik.JDY.gen!Eldorado
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.n8Z@aKF6vFh
ALYacTrojan.GenericKDZ.104367
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1416353547
TrendMicro-HouseCallTROJ_GEN.R03BC0PAK24
RisingTrojan.Injector!1.C865 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.DZQA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f85518
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba.RPY!MTB?

Trojan:Win32/Glupteba.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment