Trojan

Trojan:Win32/Glupteba!pz (file analysis)

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: CE83F451C2BBD7DB4E21.mlw
path: /opt/CAPEv2/storage/binaries/f32a0c2e03b70da2978b486ec650b2a84adf3af825de0dcf85d81d822ddcea99
crc32: 333F9BB9
md5: ce83f451c2bbd7db4e2135ba028eea8f
sha1: 4bc9c4aae1df88e5bb3e7399d5ccad96a1226fef
sha256: f32a0c2e03b70da2978b486ec650b2a84adf3af825de0dcf85d81d822ddcea99
sha512: d79343dec3e1cd73f774ceddc64531fc6a49147b099307dd9c912d4198ef6943c0e3dc794d84c24f016c529eea77511369310070f3a3ef315032edc5b0bb8779
ssdeep: 1536:mS9LqYTSNdrWV95AASPcnQ1cyJkB2+8QmkWs3nczUHsQxtJZKiubLt8c/dE:JLq+j5BskJ4fLevBtCiutzlE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17783BF5A5653ED01F9391FB43746C7A349F87C222007B7FBB65E20026AC68B39191BE9
sha3_384: 0c54af7e075040e564326d4978370d9358c9a2beef5bfddaf542ed838652d109e640d55738865b9580ff8b2df63af5dc
ep_bytes: 68000000008b3c2483c4045201c901c1
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.fuW@IHo3wXi
SkyhighBehavesLike.Win32.Glupteba.mc
McAfeeGlupteba-FTSD!CE83F451C2BB
Cylanceunsafe
VIPREGen:Trojan.Heur.fuW@IHo3wXi
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058e60a1 )
BitDefenderGen:Trojan.Heur.fuW@IHo3wXi
K7GWTrojan ( 0058e60a1 )
Cybereasonmalicious.ae1df8
BitDefenderThetaAI:Packer.4C54403D1B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.vho
AlibabaTrojan:Win32/Copak.2c55bb19
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Injector!1.CD26 (CLASSIC)
SophosTroj/Agent-BGOS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen14.3365
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ce83f451c2bbd7db
EmsisoftGen:Trojan.Heur.fuW@IHo3wXi (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminTrojan.Copak.ahss
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Heur.E84C78
ZoneAlarmHEUR:Trojan.Win32.Copak.vho
GDataGen:Trojan.Heur.fuW@IHo3wXi
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Trojan.Heur.fuW@IHo3wXi
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.4128027977
TencentTrojan.Win32.Copak.zd
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment