Trojan

Trojan:Win32/Glupteba removal instruction

Malware Removal

The Trojan:Win32/Glupteba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.

How to determine Trojan:Win32/Glupteba?


File Info:

crc32: 6D02187F
md5: c757ef47684c084a5295aff6668be65c
name: cl2.exe
sha1: ec5396982beb0c47cad420f1cb9fd5408ae02f16
sha256: 1e872bfcbcd7441cc6fb4df5bdb13a26f029c49f07125933d67f13fea7a19ae4
sha512: 5c74e43bdce715dd2f2695fe9cf4672ea63894b1664b2af75344a8de532cf43cdfa006d7c47e9cd17fb9427322b086110673effd02255c13cdf7e258d93956c0
ssdeep: 12288:2NdEgjDYrdn8WFehBYoPKazR1JH6vKAMV6KFnU9+S:2Nq3t1Y7BzRPaAS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2017
InternalName: cloudnet.exe
FileVersion: 7.2.1.1
CompanyName: EpicNet Inc.
ProductName: EpicNet Cloud Office
ProductVersion: 7.2.1.1
FileDescription: Cloud Net
OriginalFilename: cloudnet.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Glupteba also known as:

BkavW32.KillProcSMB.Worm
DrWebTrojan.Proxy2.1436
MicroWorld-eScanGen:Variant.Razy.553929
FireEyeGeneric.mg.c757ef47684c084a
CAT-QuickHealTrojan.Mauvaise.S3449555
Qihoo-360HEUR/QVM20.1.94AF.Malware.Gen
ALYacGen:Variant.Razy.553929
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005115a11 )
BitDefenderGen:Variant.Razy.553929
K7GWTrojan ( 005115a11 )
Cybereasonmalicious.7684c0
TrendMicroTrojan.Win32.GLUPTEBA.SMA
BitDefenderThetaGen:NN.ZexaF.34082.Pu0@aWlc@Wjk
F-ProtW32/Glupteba.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Dropper.Glupteba-6973164-0
GDataGen:Variant.Razy.553929
KasperskyHEUR:Trojan-Proxy.Win32.Glupteba.gen
TencentMalware.Win32.Gencirc.10b3e869
Ad-AwareGen:Variant.Razy.553929
SophosTroj/Glupteba-M
ComodoTrojWare.Win32.Glupteba.BC@82zlxv
F-SecureTrojan.TR/Crypt.XPACK.Gen2
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.553929 (B)
IkarusTrojan.Win32.Glupteba
CyrenW32/Glupteba.A.gen!Eldorado
JiangminTrojanProxy.Glupteba.adt
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Glupteba.a
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D873C9
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
ZoneAlarmHEUR:Trojan-Proxy.Win32.Glupteba.gen
MicrosoftTrojan:Win32/Glupteba
AhnLab-V3Trojan/Win32.SmearPasse.R247805
Acronissuspicious
McAfeeTrojan-FQGO!C757EF47684C
VBA32BScope.TrojanProxy.Glupteba
MalwarebytesTrojan.Glupteba
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Glupteba.BC
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.SMA
RisingTrojan.Glupteba!1.BC88 (RDMK:cmRtazrnmGSGqBRdWzFNNeMs1bb1)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Glupteba.B!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Win32.Glupteba

How to remove Trojan:Win32/Glupteba?

Trojan:Win32/Glupteba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment