Trojan

About “Trojan:Win32/Glupteba.OV!MTB” infection

Malware Removal

The Trojan:Win32/Glupteba.OV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.OV!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Glupteba.OV!MTB?


File Info:

crc32: F5B2206C
md5: 6e3931892ecdec7410c508a5989c864a
name: 6E3931892ECDEC7410C508A5989C864A.mlw
sha1: 7394ffaa4c07158f6297e8b1f810dfd3d1f225cf
sha256: 5386335debe7df955f9f8cf8e2fa0d5d482b197a3e24c59b0197eba5bf3d28b4
sha512: 96f28b5b93de0050e3b0f624edad0eaeac55951c9a8527100ff5014b8ce5172abca4f0200b56c04811954426468455341e3a066bb9fbf8fde48f0ecaea956447
ssdeep: 6144:YE+yncLehZ0TtVCmn1flTrM0+18oM80/JVhxhKgWSULvBb6TEuw7Y:cycShZ0TtVCWlTrMHBMXLh3WpJ9Y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.OV!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36436366
FireEyeGeneric.mg.6e3931892ecdec74
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.36436366
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005789b21 )
BitDefenderTrojan.GenericKD.36436366
K7GWTrojan ( 005789b21 )
Cybereasonmalicious.a4c071
CyrenW32/Kryptik.DLO.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Botx-9838326-0
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
AlibabaTrojanSpy:Win32/Glupteba.81f9ce1e
NANO-AntivirusTrojan.Win32.Noon.inpfxo
ViRobotTrojan.Win32.S.Agent.305152.DW
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareTrojan.GenericKD.36436366
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2bwc4ecrxp3hp
F-SecureTrojan.TR/Crypt.Agent.ljamy
DrWebTrojan.Fbng.50
TrendMicroTrojanSpy.Win32.NOON.THCOCBA
McAfee-GW-EditionBehavesLike.Win32.Packed.dc
SophosMal/Generic-S
IkarusTrojan-Banker.UrSnif
AviraTR/Crypt.Agent.ljamy
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan[Spy]/Win32.Noon
MicrosoftTrojan:Win32/Glupteba.OV!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D22BF98E
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataTrojan.GenericKD.36436366
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R368818
McAfeePacked-GDK!6E3931892ECD
MAXmalware (ai score=100)
VBA32BScope.Trojan.Glupteba
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HJSS
TrendMicro-HouseCallTrojanSpy.Win32.NOON.THCOCBA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/UrSnif.F628!tr
BitDefenderThetaGen:NN.ZexaF.34608.sCX@aiDoCQbG
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Generic.HwoCoVcA

How to remove Trojan:Win32/Glupteba.OV!MTB?

Trojan:Win32/Glupteba.OV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment