Trojan

Trojan:Win32/Glupteba!pz removal

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 10690EE3C6C820E1B225.mlw
path: /opt/CAPEv2/storage/binaries/5430972fbf641cb107590c86c6dd34665bcff3a3cc555204a1b2756ffb3ce421
crc32: F47E93D2
md5: 10690ee3c6c820e1b2259a5adeafb6db
sha1: 5f0dbb3d0b33de1ac701505bac6c4dd30a1d7077
sha256: 5430972fbf641cb107590c86c6dd34665bcff3a3cc555204a1b2756ffb3ce421
sha512: b7879d36157343e399b64b2c8b0460fe03ef7345247739513256d99326ddd7dfc2eb82afecb3dbccfeaa7063f9831b7f4a20f8b50a74311535c33719b2868b8a
ssdeep: 1536:AvFkhKGt6CglKLf6WXpByzVCC2euIDDhk74KmE0qD2ql9H5i1VEtTP4lexBi:pkzeL5ByzGIK+qCqlviXoTPfu
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17CA3E14FEA4643B2E28201F1138A9DD6A62ED46A33D6D9D0785CC02D25A3F28D3776D9
sha3_384: 116fe6c6d7f2bd74d49722fb91cf48596ac77ecff8e2255a0b68ec38867a07c4d2cd76bfb9715be617fefafc096ea2e5
ep_bytes: bf000000005381ee1359d424465a83ec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Glupteba.4!c
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.10690ee3c6c820e1
SkyhighBehavesLike.Win32.Glupteba.cc
ALYacGen:Variant.Razy.870640
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4386614
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/Glupteba.504d650d
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.d0b33d
ArcabitTrojan.Razy.DD48F0
BitDefenderThetaGen:NN.ZexaF.36608.guY@aejYyMk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.pa
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen22.18323
VIPREGen:Variant.Razy.870640
TrendMicroTROJ_GEN.R002C0DKU23
Trapminemalicious.high.ml.score
SophosTroj/Agent-BGOS
IkarusTrojan.Win32.Vindor
VaristW32/Kryptik.ECM.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba!pz
ZoneAlarmUDS:Trojan.Win32.Generic
GDataGen:Variant.Razy.870640
GoogleDetected
McAfeeGlupteba-FUBP!10690EE3C6C8
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3940624796
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002C0DKU23
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Agent!dNDn5PRI+sE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment