Trojan

Trojan:Win32/Glupteba.NT!MTB removal

Malware Removal

The Trojan:Win32/Glupteba.NT!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.NT!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Trojan:Win32/Glupteba.NT!MTB?


File Info:

crc32: A76E9C3F
md5: 7dd45ba3842f5d9d17232425d6c472b0
name: 7DD45BA3842F5D9D17232425D6C472B0.mlw
sha1: 13d03d0d575d3e013aaa340bb390f908fc3ccfb5
sha256: 549b6c2228553abed3348bd1858a0aab343a0b51488bf65282d2ba1f6eafc997
sha512: 7201637e0b2550bcfcc227f1362c1d7e4426768761c7370357522755a1ca2fe6dd4d913871c6ddd2efdcb6f3b32668d9d8bffdd9225ea0f966ae2a3936aa3a1f
ssdeep: 98304:wG+XeB//yL20H4BZV0X4qI18OYpv0y8pzopRquCMjgjXeUfTU4NkBAeJERBCyoT:wPXecqw4HeOp0efZEeRByAixm4Rj1F
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.2
TranslationUsa: 0x0272 0x04d3

Trojan:Win32/Glupteba.NT!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35833524
FireEyeGeneric.mg.7dd45ba3842f5d9d
Qihoo-360Generic/HEUR/QVM11.1.1A67.Malware.Gen
ALYacTrojan.GenericKD.35833524
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35833524
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d575d3
CyrenW32/Kryptik.CUR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Eb.bgm
AlibabaTrojan:Win32/GoCloudnet.e55dc57e
AegisLabHacktool.Win32.ArchSMS.lsIq
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.35833524
SophosMal/Generic-S
ComodoMalware@#1sjmqxg60rhot
F-SecureTrojan.TR/AD.GoCloudnet.spuhy
DrWebTrojan.Siggen11.56334
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.GenericKD.35833524 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Eb.gs
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.spuhy
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Glupteba.NT!MTB
GridinsoftTrojan.Win32.Kryptik.vb
ArcabitTrojan.Generic.D222C6B4
ZoneAlarmTrojan.Win32.Eb.bgm
GDataTrojan.GenericKD.35833524
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R360447
Acronissuspicious
McAfeeGenericRXAA-AA!7DD45BA3842F
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.UPX
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.FVBVBYF
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_58%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaKYSHPfG
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Glupteba.NT!MTB?

Trojan:Win32/Glupteba.NT!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment