Trojan

Trojan:Win32/Glupteba!pz malicious file

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 40F51F639EFC2A5D6A43.mlw
path: /opt/CAPEv2/storage/binaries/e34adbefe2e498db96cad9942b138817227916df818dd322e95dead3f7cdf667
crc32: C0E2885B
md5: 40f51f639efc2a5d6a435a2adcdc26a2
sha1: f7a546bd705e56ca681e1cf7ac548b9ac8091cab
sha256: e34adbefe2e498db96cad9942b138817227916df818dd322e95dead3f7cdf667
sha512: 2b5c4faaf4d84d0ad30bfac891a67abc04d5c61d705e825f317de2c76647edc690047abe15c64a44210a5e621423d724dec4a76e2dc33324ab9c00efa0fa65eb
ssdeep: 1536:sle1QQKpbUq75Qqn90RanyHrPBtyE8ba/IrEdb:9YKArn90Ray7Lie/9B
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12183F175B7072123C90A96B693A0C6BC8B3D9E57F1DE016FDD8816F9C0E3587A6A4C34
sha3_384: a2c9ca31a20c0c5d8bf124071334d100399cba8bd0ea74b7b9da7434e8a6dd42c535982b864e4b828670b41b2f8dc38b
ep_bytes: be000000005281c30100000001db81c0
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Glupteba.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.40f51f639efc2a5d
SkyhighBehavesLike.Win32.Glupteba.mc
McAfeeGlupteba-FUBP!40F51F639EFC
MalwarebytesMalware.AI.4248392046
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005304e81 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.d705e5
BitDefenderThetaGen:NN.ZexaF.36792.fuX@aejYyMk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Copak
AlibabaTrojan:Win32/Glupteba.9cbf0099
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win.Z.Razy.88576.DJ
RisingTrojan.Kryptik!1.D12D (CLASSIC)
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_GEN.R002C0DK423
Trapminemalicious.high.ml.score
SophosTroj/Agent-BGOS
IkarusTrojan.Win32.Vindor
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Razy.DD48F0
ZoneAlarmUDS:Trojan.Win32.Copak
GDataGen:Variant.Razy.870640
VaristW32/Kryptik.ECM.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R434381
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
TencentTrojan.Win32.Copak.pa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment