Trojan

Trojan:Win32/Glupteba.MZ!MTB removal

Malware Removal

The Trojan:Win32/Glupteba.MZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.MZ!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Spanish
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Glupteba.MZ!MTB?


File Info:

crc32: CA0D1EC0
md5: bcdae9f51c056a8bdfda1ab7dd9291f9
name: BCDAE9F51C056A8BDFDA1AB7DD9291F9.mlw
sha1: e25e061296177376ffb63a8679dab6294609d436
sha256: d0bef870592d1095d72178c27b2ce81dc94163aa30fa0742d6d428a1485ae459
sha512: 06e2843889fdc5106af1e92047f14b49c01b1d6601225083f370fee355d58d7ea1d180ade81fde03d10b752fba0a4096193edfae5360473af5dcd930b67109b9
ssdeep: 3072:fjnDk9LzxWoER2GsQjMBiaf/UABDjX8guvrJ6tAQBRhxBhWdGrOJhjNS6O:fbwVxWo8sQIBiYTDjru16NOJhC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: writeawasys.ets
FileVers: 1.25.381
Copyright: Copyrighz (C) 2020, gubkabob
TranslationUsa: 0x0421 0x0cd7

Trojan:Win32/Glupteba.MZ!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71236
CAT-QuickHealTrojan.Wacatac
McAfeePacked-GCZ!BCDAE9F51C05
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.71236
K7GWTrojan ( 0056fc4c1 )
K7AntiVirusTrojan ( 0056fc4c1 )
ArcabitTrojan.Generic.D11644
InvinceaMal/Generic-S
CyrenW32/Kryptik.CIT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Glupteba-9786938-0
KasperskyHEUR:Trojan.Win32.Injuke.gen
AlibabaTrojan:Win32/Glupteba.c6cde66a
RisingTrojan.Kryptik!1.CE5E (CLASSIC)
Ad-AwareTrojan.GenericKDZ.71236
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.Agent.vbnac
DrWebTrojan.DownLoader35.16737
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PK620
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.bcdae9f51c056a8b
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.vbnac
MAXmalware (ai score=100)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Glupteba.MZ!MTB
ZoneAlarmHEUR:Trojan.Win32.Injuke.gen
GDataTrojan.GenericKDZ.71236
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R354985
Acronissuspicious
ALYacTrojan.Agent.ZLoader
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHGR
TrendMicro-HouseCallTROJ_GEN.R002C0PK620
TencentWin32.Trojan.Injuke.Pjxi
IkarusTrojan.Win32.Glupteba
eGambitUnsafe.AI_Score_82%
FortinetW32/Kryptik.CIT!tr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.296177
AvastWin32:DropperX-gen [Drp]
Qihoo-360Generic/HEUR/QVM10.2.13AA.Malware.Gen

How to remove Trojan:Win32/Glupteba.MZ!MTB?

Trojan:Win32/Glupteba.MZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment