Trojan

Trojan:Win32/Glupteba.RQ!MSR removal guide

Malware Removal

The Trojan:Win32/Glupteba.RQ!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.RQ!MSR virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Collects information about installed applications
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Glupteba.RQ!MSR?


File Info:

crc32: E9EFB478
md5: 913b155d99a6f2cff3cfb7efb37510ba
name: asura.exe
sha1: 441a7988b4320cb739e2bb8a38f21839299617e1
sha256: 1a9d32cb43faca5bc1b4e823181fb2054765dbec5f2adfd6fed833d2716436bd
sha512: 140198cf263772f8af32958aa9fa443da7e43d0b397e3dc72227f9e9e345d3ef861a7e14ba72e0739e6b3f3446d0ad99119d75a1fc55c524d4f6cfb06b5e97a0
ssdeep: 98304:2Qg6ZV+TLBFSIZM7fYhDr1EgLaotdJUuwzdrgMZU/3htDbd8:2cZCLz/GYzaot/UuwBr9GxtF8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: wriheovbz.ote
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, pumke
TranslationUsi: 0x0431 0x0ccd

Trojan:Win32/Glupteba.RQ!MSR also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34956188
FireEyeGeneric.mg.913b155d99a6f2cf
ALYacTrojan.GenericKD.34956188
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00571db81 )
BitDefenderTrojan.GenericKD.34956188
K7GWTrojan ( 00571db81 )
Cybereasonmalicious.8b4320
TrendMicroTrojan.Win32.GLUPTEBA.THJBGBO
CyrenW32/Ulise.BU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-9784859-0
KasperskyHEUR:Trojan-PSW.Win32.Tepfer.gen
AlibabaTrojanPSW:Win32/Glupteba.66aba318
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!1.CE27 (CLASSIC)
Ad-AwareTrojan.GenericKD.34956188
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.GenericKD.34956188 (B)
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Glupteba.RQ!MSR
ArcabitTrojan.Generic.D215639C
ZoneAlarmHEUR:Trojan-PSW.Win32.Tepfer.gen
GDataTrojan.GenericKD.34956188
CynetMalicious (score: 100)
Acronissuspicious
McAfeePacked-GCZ!913B155D99A6
VBA32Trojan.Azorult
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHAU
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.THJBGBO
TencentWin32.Trojan-qqpass.Qqrob.Hqbj
IkarusTrojan.Win32.Glupteba
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EVDR!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
Qihoo-360Win32/Trojan.PSW.61a

How to remove Trojan:Win32/Glupteba.RQ!MSR?

Trojan:Win32/Glupteba.RQ!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment