Trojan

Trojan:Win32/Glupteba.G!MSR removal guide

Malware Removal

The Trojan:Win32/Glupteba.G!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.G!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
puffpuff421.top

How to determine Trojan:Win32/Glupteba.G!MSR?


File Info:

crc32: 76A86EB6
md5: 82003e22dcbee79020b39b85aae3a635
name: 82003E22DCBEE79020B39B85AAE3A635.mlw
sha1: b766d0ec2d690d78571d4039be42eeb28990fa3c
sha256: 18037c34b9aafe45a8cd0743c637eac4abc50cfd6b14bd678bac6620ade45401
sha512: 12e1769ebc4d911313b1de63c0a0645aec35bdb669875d4304b8cba8315aa73429cab33343fbf613a0ba531d169400391dfd58f1828e98a1a7847b85e7f81d4f
ssdeep: 12288:VoVhif2ybAlbf1MT8WPWBdGtROAV64qKs7KnJKjzaLQAe:4sYlbVWPydGtROAV64IKIzO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: smogbag.exe
ProductionVersus: 1.2.7.33
Copyrights: Copyrighds (C) 2020, xghk
FileVersion: 1.2.8
TranslationUsi: 0x0772 0x0cd7

Trojan:Win32/Glupteba.G!MSR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.53962
MicroWorld-eScanTrojan.GenericKDZ.69763
FireEyeGeneric.mg.82003e22dcbee790
McAfeePacked-GCZ!82003E22DCBE
MalwarebytesTrojan.MalPack.GS
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005579741 )
BitDefenderTrojan.GenericKDZ.69763
K7GWTrojan ( 005579741 )
Cybereasonmalicious.2dcbee
CyrenW32/Kryptik.BUU.gen!Eldorado
SymantecPacked.Generic.525
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Glupteba-9622151-0
KasperskyHEUR:Trojan.Win32.Chapak.vho
Ad-AwareTrojan.GenericKDZ.69763
F-SecureHeuristic.HEUR/AGEN.1138815
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.GenericKDZ.69763 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138815
MicrosoftTrojan:Win32/Glupteba.G!MSR
GridinsoftTrojan.Heur!.02852021
ArcabitTrojan.Generic.D11083
ZoneAlarmHEUR:Trojan.Win32.Packect.gen
GDataTrojan.GenericKDZ.69763
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKDZ.69763
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HFUE
RisingTrojan.Kryptik!1.CB4D (CLASSIC)
MAXmalware (ai score=84)
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.HFTR!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.352F.Malware.Gen

How to remove Trojan:Win32/Glupteba.G!MSR?

Trojan:Win32/Glupteba.G!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment