Trojan

Trojan:Win32/Glupteba!pz information

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: B6A0A2877BC784AB15AE.mlw
path: /opt/CAPEv2/storage/binaries/f9d3339da8a6db1d618677ae0b1ce8395297fd761e695b695f9c5f017c595b40
crc32: 4F5772BB
md5: b6a0a2877bc784ab15aeb68275e8532d
sha1: 0e2c67a8d4e2e07838a7c278bfba584f3fb38a86
sha256: f9d3339da8a6db1d618677ae0b1ce8395297fd761e695b695f9c5f017c595b40
sha512: 423b2362925f33926c9003f79699c5eed3c651304ba1ee8b01814f70287ba8ecbc2a9db58a3fc64ab55909c5c27bbba697a1b840a399e9a844e323f7e9b6934f
ssdeep: 1536:k/K/c9NYjFR+CEVu5sXBBFiKiTINMNJED0G2xlcQb6kT7MFS2:e9+DpEMyXViKcI2jED0G2xmafAN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12E83F148EE230233D77CA57803C615440D6F3E576B4B8ADFF59A532A94984E948BEC3A
sha3_384: ba7b9f891ed3242d923919dac727af7b93d2f4b3578f0bf0d364e83b49999eb23732801439e60ee7b0d0961b1f428914
ep_bytes: b800000000564f4f5909d75109d781ea
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.b6a0a2877bc784ab
SkyhighBehavesLike.Win32.Glupteba.mc
ALYacGen:Variant.Razy.870640
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005304e81 )
K7AntiVirusTrojan ( 0058c5ff1 )
ArcabitTrojan.Razy.DD48F0
BitDefenderThetaGen:NN.ZexaF.36792.fuX@aejYyMk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-10012879-0
KasperskyVHO:Trojan.Win32.Injuke.gen
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.pa
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.moderate.ml.score
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
VaristW32/Kryptik.ECM.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=87)
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba!pz
ZoneAlarmVHO:Trojan.Win32.Injuke.gen
GDataGen:Variant.Razy.870640
GoogleDetected
McAfeeGlupteba-FUBP!B6A0A2877BC7
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.8d4e2e
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment