Trojan

What is “Trojan:Win32/Glupteba!pz”?

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 1B2D0697FE09102D9507.mlw
path: /opt/CAPEv2/storage/binaries/f0e81b3029d327d9f422d1464c0d6a948929830282490f79ed5b30fe1c647501
crc32: 964459D1
md5: 1b2d0697fe09102d95073306e3aa22a3
sha1: 4a1cb81ed432e495b35184c7dbf1c10d94c9ec8c
sha256: f0e81b3029d327d9f422d1464c0d6a948929830282490f79ed5b30fe1c647501
sha512: 4e49ba6e1f4896023783d56922dad485e7b5d7727b87749e288dcb4e5d255e0ccea5466d527db912be46c5355173e2c2d279004baf2878ec99785fb9b9b17f8f
ssdeep: 1536:aH+qdngKAZm7pEyPHOpXs/9KCwNx94Fg+EJznw5IgNhc61kVSW2Qe1pCKa:kngHmcpc/9LG94Fgtzw5l3M2Qe1YKa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1818302A5CD86970BCF0A4B368781A0806DBCD75F3045701EF994C0A7AB5F8E5E6CA5E4
sha3_384: eb01a4afdaaa91c3e8526c7e3a4a84797ffe4423935abe5786634204b2fd919d2a67ea910f20e8b2af37f4a78326c92e
ep_bytes: b8000000005181c69adef65c5abf90c4
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.870640
SkyhighBehavesLike.Win32.Glupteba.mc
McAfeeGlupteba-FUBP!1B2D0697FE09
MalwarebytesMalware.AI.4196463730
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 005304e81 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.DD48F0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.pa
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen21.21748
ZillyaTrojan.Kryptik.Win32.4362021
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1b2d0697fe09102d
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cwnh
VaristW32/Kryptik.ECM.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.996
MicrosoftTrojan:Win32/Glupteba!pz
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.870640
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.fuW@aa@5Hcm
ALYacGen:Variant.Razy.870640
TACHYONTrojan/W32.Copak.86528.DRC
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Copak!8WPHkcD2aLs
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.ed432e
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment