Trojan

Trojan.Glupteba.S17270700 removal

Malware Removal

The Trojan.Glupteba.S17270700 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Glupteba.S17270700 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Glupteba.S17270700?


File Info:

name: 2F2DE13E1CE43BFE83FE.mlw
path: /opt/CAPEv2/storage/binaries/9f391baf98f1365df39ba792ba5afc14f84fa6c886b0f3da5fb6416aa1771ab1
crc32: BA61F062
md5: 2f2de13e1ce43bfe83fece5534c0e60a
sha1: 52105b266be8015ccaf87338ccb2e7ba05642f92
sha256: 9f391baf98f1365df39ba792ba5afc14f84fa6c886b0f3da5fb6416aa1771ab1
sha512: 4acf5add446a4286fe0c7ccaf15d7fc091420e684956bb56681e181f0a4ed2815f5f717931409b656dc3269e68ddddad15900f3c2eb2f9f57ad2e1c3edd011cf
ssdeep: 12288:9K/8/MF/0yXZTTrbcol8zie973wEnw3MZCRXC7ADn+Zcol8zie973wE:V2cypTTxGU3SCC7Ay3G
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E905D0F6D216FAA2C3F803741B97A6A315B77AED031667D976A0468D4BB300075FC62C
sha3_384: e0a2cbfc4275b9f3cf7e2e2062f7f87aadf38f8251367ed80bbd39c387d9d1e45ca5b135878eef72bca68c177c5ab88a
ep_bytes: eb26a340bb4f27c7beae2e56acec46ec
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Trojan.Glupteba.S17270700 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.71586230
FireEyeGeneric.mg.2f2de13e1ce43bfe
CAT-QuickHealTrojan.Glupteba.S17270700
SkyhighBehavesLike.Win32.Trojan.bc
McAfeeTrojan-FVOQ!2F2DE13E1CE4
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.71586230
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.X4Z@aiNtz3j
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
ClamAVWin.Packed.Razy-9873099-0
KasperskyUDS:Trojan.Win32.Selfmod.gen
BitDefenderTrojan.GenericKD.71586230
NANO-AntivirusTrojan.Win32.Kryptik.fftmao
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
EmsisoftTrojan.GenericKD.71586230 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Kryptik.Win32.3263580
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
GDataWin32.Trojan.PSE.11XGYE9
JiangminTrojan.Generic.clctx
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D44451B6 [many]
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.R620290
Acronissuspicious
VBA32Trojan.Khalesi
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Copak.kq
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Glupteba.S17270700?

Trojan.Glupteba.S17270700 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment