Trojan

Should I remove “Trojan:Win32/Glupteba.PQ!MTB”?

Malware Removal

The Trojan:Win32/Glupteba.PQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.PQ!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Trojan:Win32/Glupteba.PQ!MTB?


File Info:

crc32: 51C1A165
md5: b6b02648ddfc6a19e245420e37c855a7
name: B6B02648DDFC6A19E245420E37C855A7.mlw
sha1: bad256e19930cc33e1add35a9863e3cb88710762
sha256: 9d8cc2da96af9bb56881796ebeace41e1ae42cc71fb352a2526d2da7bae1c097
sha512: 986c979eab2e49a9ca222024fc39b3af31f20c24fc8eb3a3affc9f013ced485bdd83dd0c65a22dff92114ac75b1e27028e7f99e9218cba171c18fe4d1e860f7c
ssdeep: 6144:GgLi+k6KsLND3JivDz8mX2TUPECuGQt/4to00ysOQN7khQ12gVisfkZvZ4+y/DT:TG+k6XB56U42TXfZbvV0QfqyXDLHpa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVerus: 1.0.52.18
ProductVersys: 1.8.37.29
Translations: 0x0186 0x03de

Trojan:Win32/Glupteba.PQ!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.64757
CynetMalicious (score: 100)
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.19930c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKOW
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKD.36785435
MicroWorld-eScanTrojan.GenericKD.36785435
Ad-AwareTrojan.GenericKD.36785435
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.snoez@0
BitDefenderThetaGen:NN.ZexaF.34684.FqW@a4GbI9eO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
FireEyeGeneric.mg.b6b02648ddfc6a19
EmsisoftTrojan.GenericKD.36785435 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.PQ!MTB
AegisLabTrojan.Win32.Convagent.i!c
GDataTrojan.GenericKD.36785435
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNTDQ21
RisingTrojan.Kryptik!1.D4E6 (CLOUD)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HKOJ!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Glupteba.PQ!MTB?

Trojan:Win32/Glupteba.PQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment