Trojan

About “Trojan:Win32/Glupteba!pz” infection

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 6CA60C75E779D534E762.mlw
path: /opt/CAPEv2/storage/binaries/a49c35531cbfa6a9f31e459cbda7f4eb58b2c67e2852d7b63724bef37fd7fa8a
crc32: E46DE9BF
md5: 6ca60c75e779d534e762987a0bb79d5a
sha1: 37d8bcf156570c2f1dcbe1a6af79203df6bd9218
sha256: a49c35531cbfa6a9f31e459cbda7f4eb58b2c67e2852d7b63724bef37fd7fa8a
sha512: 136fd69a0e14ce894ff703057d7313f0129239b275119ff459b1b9d4138d6f4d4422923b32751ce15798e77289af7d6276d4ee63177a67b3086a18bfe1dba794
ssdeep: 1536:sT60HbguONlGg/Qr4xOvwSx+kOvOfjdtePzZ1EuJRfam7TeXmXecvp3UN8V:H0HuGgJ5i+kOvOjdk7Hv7a2rNN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13104D1FA19021C97CD3071F2206C2050776FD7B7FAC95DAB9E51F139ADB001E16A16E9
sha3_384: 15dbdd3df8a471a27274ed88c076fbfc97b74ab32918abffe8ead851a73b67fffcf2be38abe5db343c866aaffbc0f668
ep_bytes: 47a9ad348e6aad34dbe348b9ea4e6962
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Lazy.425525
FireEyeGeneric.mg.6ca60c75e779d534
CAT-QuickHealTrojan.Glupteba
SkyhighBehavesLike.Win32.RAHack.ct
McAfeeArtemis!6CA60C75E779
MalwarebytesMalware.AI.3992733119
VIPREGen:Variant.Lazy.425525
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Lazy.425525
Cybereasonmalicious.156570
BitDefenderThetaGen:NN.ZexaF.36792.luZ@aaoz!!o
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Packed.Iho3wxi-9880829-0
AlibabaTrojan:Win32/Glupteba.085c0d82
RisingTrojan.Injector!1.CD26 (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R03BC0DK623
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.425525 (B)
IkarusTrojan.Win32.Crypt
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Lazy.D67E35
GDataGen:Variant.Lazy.425525
CynetMalicious (score: 100)
ALYacGen:Variant.Lazy.425525
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DK623
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment