Trojan

What is “Trojan:Win32/Glupteba!pz”?

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 483DD0218C798FBE1909.mlw
path: /opt/CAPEv2/storage/binaries/5c0ec3afccd37d0288b0ecfa2cb385f9a7c9d16c543efc28e53d43922b1005f0
crc32: C57A048A
md5: 483dd0218c798fbe1909381a052cea81
sha1: bbf3df0c4cffefcfd444aab2dd994dbd785d335f
sha256: 5c0ec3afccd37d0288b0ecfa2cb385f9a7c9d16c543efc28e53d43922b1005f0
sha512: 6f5a72d065d6792766d4aa19801469a50488fba0b06f94ebfdda29279c95bfcd61f22336ea2dda0b1d303e5076de7d6c17bbea1ab38563541c466d0905be1b98
ssdeep: 3072:+e1StKgCzTKWjGc5JW2sKsRuUrdY7zcnpW9sz3GXZo0scMqF2DeP3mLPx1I6zajG:+eMtfCzT4c5Jm6q1Y23GJo0scxFQ43AD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T194041267E38313B6F08403B152CEE0C2197D9DEB3036957AD74968E922ED71C86F85B8
sha3_384: 39f943d74c9398229c0fd09c041cc1d11b7f71d8cbe9778aa8eefb002ddd3da7fe5e953457a410591de3a6f2085dc442
ep_bytes: ba000000005109f85b09c001f883ec04
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.870640
ClamAVWin.Packed.Razy-9874932-0
SkyhighBehavesLike.Win32.Glupteba.cc
McAfeeGlupteba-FUBP!483DD0218C79
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058dcbc1 )
K7GWTrojan ( 005304e81 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.DD48F0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.agacg
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Dropper.Gen
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.483dd0218c798fbe
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Glupteba!pz
ZoneAlarmTrojan.Win32.Copak.agacg
GDataGen:Variant.Razy.870640
VaristW32/Kryptik.ECM.gen!Eldorado
AhnLab-V3Trojan/Win.FUBP.R618951
BitDefenderThetaGen:NN.ZexaF.36608.luZ@aejYyMk
ALYacGen:Variant.Razy.870640
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
TencentTrojan.Win32.Copak.pa
YandexTrojan.Copak!KG5+iBNn9NE
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.c4cffe
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment