Trojan

What is “Trojan:Win32/Glupteba!pz”?

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: A99B5687CAE43FEC19C5.mlw
path: /opt/CAPEv2/storage/binaries/917c894da06224c15289991037e15f1df91e3ff96d0c265bcd48067cc5423e2a
crc32: CDFD7374
md5: a99b5687cae43fec19c5057fb3c41e87
sha1: 69b5344e8dc0261767329ef5249a8f46d3e9e860
sha256: 917c894da06224c15289991037e15f1df91e3ff96d0c265bcd48067cc5423e2a
sha512: b2be3bd1bd26f42c0d0a2a7d9118f19d18593a1be8cf4cd64019c3d5c69bb0d743c10fbc64a9b35be8c44476440b1eb1fd85583faaa6d4e26b6c6deb546f6ac4
ssdeep: 1536:4wVEICkhsgMF1peZ2z4WqQEIytfVLa82nj3RWmlP1E5WNdo2SABGzY:4cEIf5C1pecxtyBg7hf1IHp+D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D48301A52D2703D9F155E97BF721F2F026758F8F9A4220AF44D140E2E97C426279BF20
sha3_384: 90e80428a72cce63ef363474a999522da26fa58267def9a15b822810e62354c6e3098c00794b75cee2386bbcf3a80376
ep_bytes: bb000000005281c60100000081c62229
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.a99b5687cae43fec
SkyhighBehavesLike.Win32.Glupteba.mc
McAfeeGlupteba-FUBP!A99B5687CAE4
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.102955
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005304e81 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.e8dc02
BitDefenderThetaGen:NN.ZexaF.36792.fuX@aejYyMk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Convagent.gen
AlibabaTrojan:Win32/Glupteba.b318a156
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Injector!1.C865 (CLASSIC)
SophosTroj/Agent-BGOS
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Razy.870640
TrendMicroTROJ_GEN.R002C0DK423
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.870640 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.870640
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.4118415686
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
TencentTrojan.Win32.Copak.pa
YandexTrojan.Copak!AVaCXzroNQI
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment