Trojan

Trojan:Win32/Glupteba!pz removal

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 7E6ADE016BBBD20EC884.mlw
path: /opt/CAPEv2/storage/binaries/4d7795b35c790375be26ca4664b1d306b816c3aa5a4923aeae3ab89836682033
crc32: B0FD92FB
md5: 7e6ade016bbbd20ec884112ae1b00619
sha1: 893ffe90f5477f20c3b858bb58886ce9bbfbd118
sha256: 4d7795b35c790375be26ca4664b1d306b816c3aa5a4923aeae3ab89836682033
sha512: 260e108f8700198e34181bfa82421f4f6d6e2477424bf1a749ebb32cecf748f5b1743dec22b3d65d9875c8d3b059795cb249cd1f944a746fc5045b3368631276
ssdeep: 3072:4//QlKg4kqGruoK5fsUDQU/+6QwfD7R/LOX4H:4gsGy/sIQU/+6PR/LOX4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DEA3E15BB64A1773D2C004B66B4E88C13B3C863B32E781AE5068455D0373DE99BFB6D8
sha3_384: 4fc5c9960d29e4651ef5bf6258ab8927e6769cbc167b73b43317c1149324db152364d695c3da1215286fddde15e2e4e9
ep_bytes: ba0000000083ec04890c2481eec48eb8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
SkyhighBehavesLike.Win32.RAHack.nc
ALYacGen:Variant.Razy.870640
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.0f5477
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Convagent.gen
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Injector!1.C865 (CLASSIC)
SophosTroj/Agent-BGOS
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Razy.870640
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7e6ade016bbbd20e
EmsisoftGen:Variant.Razy.870640 (B)
IkarusTrojan.Win32.Injector
MAXmalware (ai score=85)
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Glupteba!pz
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
McAfeeGlupteba-FUBP!7E6ADE016BBB
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
TencentTrojan.Win32.Copak.pa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
BitDefenderThetaGen:NN.ZexaF.36792.guY@aejYyMk
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment