Trojan

Trojan:Win32/Glupteba.OE!MTB removal guide

Malware Removal

The Trojan:Win32/Glupteba.OE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.OE!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
mynameisalfred.top

How to determine Trojan:Win32/Glupteba.OE!MTB?


File Info:

crc32: D8A5F40C
md5: 186174817871c21ba0dd93d05b12110f
name: 186174817871C21BA0DD93D05B12110F.mlw
sha1: aa2fb0e6c959446aaa25ca3672651c53d09aa773
sha256: 13e13c9a09af45bd0705d94ff3d7fc95d5d5911311d25a034e9136b80dcf834d
sha512: d1e58e05392fb03b5010ba63e779e97fabe88f0249941c13f02fa0ee19f901662f5010a7e6ed0d5ad821af7b7dcb70462aec56a73154f2d6644d1bbcc295389e
ssdeep: 12288:z709LSUOxKHdVMK2jXVlO/aHYT3javjWrrrIEpH:zqSFUWBoi46SrHB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.OE!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45637147
FireEyeGeneric.mg.186174817871c21b
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00569e421 )
BitDefenderTrojan.GenericKD.45637147
K7GWTrojan ( 00569e421 )
Cybereasonmalicious.6c9594
CyrenW32/Kryptik.DCH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Exploit.Win32.Shellcode.gen
RisingTrojan.Kryptik!8.8 (TFE:5:U5s8Xe4IxnO)
Ad-AwareTrojan.GenericKD.45637147
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Siggen2.61325
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.gc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Glupteba.OE!MTB
ArcabitTrojan.Generic.D2B85E1B
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataWin32.Trojan-Stealer.Raccoon.JQD5JV
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4312547
Acronissuspicious
McAfeeGenericRXAA-AA!186174817871
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
ESET-NOD32a variant of Win32/Kryptik.HJCD
IkarusTrojan.Win32.Ranumbot
FortinetW32/GenericKDZ.3848!tr
BitDefenderThetaGen:NN.ZexaF.34780.BqW@a46SuVfO
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.E90E.Malware.Gen

How to remove Trojan:Win32/Glupteba.OE!MTB?

Trojan:Win32/Glupteba.OE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment