Trojan

Should I remove “Trojan:Win32/Glupteba!pz”?

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: 01E0819C4CA50FD4C1B2.mlw
path: /opt/CAPEv2/storage/binaries/9a53defb245032cc538c96fa2742599b59b8cbc0b39488c022750325ea211bbf
crc32: E4E7D24F
md5: 01e0819c4ca50fd4c1b2c5c18ef61f9a
sha1: 3f24c3642c603ba91ed14a494819bd56380784bb
sha256: 9a53defb245032cc538c96fa2742599b59b8cbc0b39488c022750325ea211bbf
sha512: 3d48428d91f039c222d0b275a581198629f8f3376382d390fa3eabadd4f263247f75084f062e1771012e9ddada693e0156a9acb7cb4ec1fbb5491ec425d168a3
ssdeep: 1536:yi8IHJfc2BEW7d+qgq1t0SII1fC3+Z4I2EGqP+:kIHq2BBx3TII1fC3+yI2EGqP+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F28302839D85102AF5075EB09AF680CE375B48CB25CAA13FFE48A30D75D655C2794AF1
sha3_384: f339d5ae62f23eaa2d044fdc7bffa163fd2f1aa5625efa5430dadf660928721f52e48fc4f359637c9a7ec30b9bf0403e
ep_bytes: bf0000000053ba5d97bfb181e97989fc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.01e0819c4ca50fd4
SkyhighBehavesLike.Win32.Glupteba.mc
ALYacGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 005304e81 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaCO.36802.fuW@aejYyMk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
AvastWin32:Evo-gen [Trj]
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentTrojan.Win32.Copak.pa
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.high.ml.score
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Kingsoftmalware.kb.a.994
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
McAfeeGlupteba-FUBP!01E0819C4CA5
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
RisingTrojan.Kryptik!1.D635 (CLASSIC)
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.c4ca50
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment