Trojan

What is “Trojan:Win32/Glupteba.DHD!MTB”?

Malware Removal

The Trojan:Win32/Glupteba.DHD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.DHD!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Gaelic (Scottish)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Glupteba.DHD!MTB?


File Info:

crc32: 55B83825
md5: 3f2ad3ee853143348ebc182db8254dbc
name: svchost.exe
sha1: fdad37d7a96ce1a11e5e96924967ef48bbc6f4b2
sha256: 4f93c2499155c0860091d49c48525612acfdf145dff7c12ecf35ae0217cbd8f7
sha512: 679616adcdbec41b6fa8efc3154153f973c4f45a695bc8d5faeb613a32145a5e57468c84b214322bfa02112b7179a805c06561e863592d49f59463189c83b8b1
ssdeep: 6144:E/Z4tzH8HuGXKU1n9FCIrbI2NdZgOAiz2TGSWlK4kTQI:O4lbIpn94I4uXIiz2uQ7TQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalServiceName: sfsgvsdg.exe
Copyright: Copyright (C) 2020, tail
FileVersionFull: 2.3.4

Trojan:Win32/Glupteba.DHD!MTB also known as:

MicroWorld-eScanGen:Variant.Midie.70495
FireEyeGeneric.mg.3f2ad3ee85314334
Qihoo-360HEUR/QVM10.1.445D.Malware.Gen
McAfeeArtemis!3F2AD3EE8531
MalwarebytesTrojan.MalPack.GS
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderGen:Variant.Midie.70495
K7GWTrojan ( 005608261 )
Cybereasonmalicious.7a96ce
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34090.tOW@aSaYXqcG
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DBE20
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7561022-0
GDataGen:Variant.Midie.70495
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareGen:Variant.Midie.70495
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.eankw
DrWebTrojan.PWS.Siggen2.43597
TrendMicroTROJ_GEN.R002C0DBE20
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Midie.70495 (B)
APEXMalicious
AviraTR/Crypt.Agent.eankw
Endgamemalicious (high confidence)
ArcabitTrojan.Midie.D1135F
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Glupteba.DHD!MTB
AhnLab-V3Trojan/Win32.MalPe.R325568
Acronissuspicious
ALYacGen:Variant.Midie.70495
MAXmalware (ai score=85)
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBBG
IkarusTrojan.Win32.Kovter
FortinetW32/Kryptik.HBAV!tr
AVGWin32:CoinminerX-gen [Trj]
AvastWin32:CoinminerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba.DHD!MTB?

Trojan:Win32/Glupteba.DHD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment