Malware

Should I remove “Troj/Gupboot-B”?

Malware Removal

The Troj/Gupboot-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gupboot-B virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Gupboot-B?


File Info:

name: D7F30F570AA8C2100047.mlw
path: /opt/CAPEv2/storage/binaries/8a40390d7b8185a8cbbb1d3bf5f0d083f725f99c126b65cace314538bf58f4cd
crc32: E559AE5F
md5: d7f30f570aa8c21000471333c47a84a1
sha1: 2b8fa1327ec88cd6b0bfbb97d7111af173282885
sha256: 8a40390d7b8185a8cbbb1d3bf5f0d083f725f99c126b65cace314538bf58f4cd
sha512: b92ef56f3009a684ba8238045d2319a87ef1ea925afe66f0a88c60ec4d2ee575004c5645c0ec23767f2261aac41aeba1a13ce675cf5667badad25316d31c01f5
ssdeep: 12288:AJXA2BueJQYZ53kj8hIt7axPIGl741yGY9xoAUKyl3dseqIvcO3viiV8K:AJ1BuyYpadIg741NxKW3dJrv1f2K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB25E1206640D075E3AA037445A7E6F1196CAE356798D18FF3B8BE7A6E302D3563324F
sha3_384: 51810bfb00314cf17c63a2dd07c6f2c1e56d608f51a57b0e7b4c7ca0c1a906e5a75d1b4cf64ea4593c3b26e66b67f293
ep_bytes: e80f740000e979feffff8bff558bec81
timestamp: 2012-10-19 05:46:29

Version Info:

CompanyName: ASPack
FileDescription: Asp Packer
FileVersion: 1, 0, 0, 85
InternalName: Security
LegalCopyright: Copyright (C) 2012
OriginalFilename: AspUp.exe
ProductName: Exe Packing Security
ProductVersion: 1, 0, 0, 85
Translation: 0x0412 0x04b0

Troj/Gupboot-B also known as:

BkavW32.AIDetectMalware
DrWebTrojan.AVKill.24205
MicroWorld-eScanTrojan.GenericKD.38933884
ClamAVWin.Trojan.R-102
CAT-QuickHealTrojan.Gupboot.B.mue
McAfeeTrojan-FCSU!D7F30F570AA8
MalwarebytesUrelas.Trojan.Downloader.DDS
ZillyaTrojan.Urelas.Win32.355
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0051170b1 )
K7GWBackdoor ( 0051170b1 )
Cybereasonmalicious.70aa8c
BitDefenderThetaGen:NN.ZexaF.36250.8m3@ay3cs3gO
VirITTrojan.Win32.Crypt.BQAW
CyrenW32/FakeSec.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.AR
APEXMalicious
CynetMalicious (score: 100)
KasperskyRootkit.Win32.Plite.pfa
BitDefenderTrojan.GenericKD.38933884
NANO-AntivirusTrojan.Win32.AVKill.bdepgw
SUPERAntiSpywareTrojan.Agent/Gen-FakeSec
AvastWin32:Urelas-B [Trj]
TencentRootkit.Win32.Plite.a
EmsisoftTrojan.GenericKD.38933884 (B)
F-SecureBackdoor.BDS/Backdoor.Gen6
BaiduWin32.Rootkit.Agent.s
VIPRETrojan.GenericKD.38933884
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d7f30f570aa8c210
SophosTroj/Gupboot-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.13LF282
JiangminBackdoor.Generic.wfi
WebrootW32.Trojan.Gen
AviraTR/Graftor.884956
Antiy-AVLTrojan[Rootkit]/Win32.Plite
XcitiumTrojWare.Win32.Urelas.BK@5ol715
ArcabitTrojan.Generic.D252157C
ZoneAlarmRootkit.Win32.Plite.pfa
MicrosoftTrojan:Win32/Gupboot!atmnm
GoogleDetected
AhnLab-V3Trojan/Win32.PbBot.R35329
Acronissuspicious
VBA32Rootkit.Plite
ALYacTrojan.GenericKD.38933884
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Agent!1.9CB5 (CLASSIC)
YandexRootkit.Plite!BzZ6fCHfhmk
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.6037960.susgen
FortinetW32/Urelas.F!tr
AVGWin32:Urelas-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Gupboot-B?

Troj/Gupboot-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment