Trojan

Trojan:Win32/Glupteba!pz information

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 3C11B3A286336AAFC5F8.mlw
path: /opt/CAPEv2/storage/binaries/d8ee8c85f09a519d6536565a594bdab51faee3feadeab2ce9a6f99e6f34475ee
crc32: CB291B14
md5: 3c11b3a286336aafc5f88d6f844c3781
sha1: f3fa16b188297d9c2dd38336fd2ab50a37e10573
sha256: d8ee8c85f09a519d6536565a594bdab51faee3feadeab2ce9a6f99e6f34475ee
sha512: e4d7b7c76798653ac2c13e25147a1a9e05fbc33645dfc83a1f76459d37b945221a648187575479369a06956e79d63e759ff718bb5095a51297aebbe66eb66696
ssdeep: 3072:KGMJYzN+al8+fMQPf15jtoqlAkhW8pW9sz3GXZo0scMqF2DeP3mLPx1I6zajG:Z+Yzob+fpPzjrlAkhDY23GJo0scxFQ4+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10904125BBBD317F7FAD80432828510C7182F5C57309BA5D2C5EA885E156AE8DDB78E30
sha3_384: 536f9928aa36a9e62746b47ce1ce5e9ce98ca25f7d4e788cb43db5be1e523ccac01ef786e451d1e632b32b15f950d5d4
ep_bytes: b90000000083ec0489142409df5e29ff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Variant.Razy.870640
SkyhighBehavesLike.Win32.Glupteba.cc
McAfeeGlupteba-FUBP!3C11B3A28633
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058dcbc1 )
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.188297
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03BC0DC324
ClamAVWin.Packed.Razy-9874932-0
KasperskyTrojan.Win32.Copak.agacg
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.pa
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen27.686
TrendMicroTROJ_GEN.R03BC0DC324
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3c11b3a286336aaf
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
VaristW32/Kryptik.ECM.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Razy.DD48F0
ZoneAlarmTrojan.Win32.Copak.agacg
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R618951
BitDefenderThetaGen:NN.ZexaF.36744.luZ@aejYyMk
ALYacGen:Variant.Razy.870640
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Copak!KG5+iBNn9NE
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment