Trojan

About “Trojan:Win32/Gupboot!atmnm” infection

Malware Removal

The Trojan:Win32/Gupboot!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gupboot!atmnm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Gupboot!atmnm?


File Info:

name: DB81F2F8656BB6658269.mlw
path: /opt/CAPEv2/storage/binaries/9368de7875eae139f9e0dbdbf204650d0011f071037b356bbeae66753e3e43d9
crc32: 2E351A21
md5: db81f2f8656bb66582692cc00421242a
sha1: d9ebe4ca9b0ebb86985bfdd6e5ca3ebc4998583e
sha256: 9368de7875eae139f9e0dbdbf204650d0011f071037b356bbeae66753e3e43d9
sha512: b18e0792cd5fb5ad6158ca57e5615c91be71fc82014c751d320b0934459470ffa33b07cb0d46c6e843d1d81f16ac364911b0b847a0f65280ccd7def4d34a6a26
ssdeep: 12288:vwCXnLquXU99ICYj7xrcqPkePh+RvMaBlYJQCe2m9Or:oFn9pYjFMePh+RpBlU69Or
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E885DF2D7A4C9071E7A90B714432E6B50D696C3906A4A5CFF7783E3A6D312D3867328F
sha3_384: 4b401b63915b010446c94cd61a4f577594797b533945bc1ff1029129d231502174cbe5838328ac1e6c4b72cd0b48dc1c
ep_bytes: e8b0750000e979feffff8bff558bec81
timestamp: 2012-11-09 07:14:38

Version Info:

CompanyName: Apple
FileDescription: Apple iCloud
FileVersion: 1, 0, 0, 85
InternalName: Apple New Ipad
LegalCopyright: Copyright (C) 2012
OriginalFilename: app stroe
ProductName: Apple iPad
ProductVersion: 1, 0, 0, 85
Translation: 0x0412 0x04b0

Trojan:Win32/Gupboot!atmnm also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.82870
FireEyeGeneric.mg.db81f2f8656bb665
CAT-QuickHealTrojan.Swisyn.16719
McAfeeTrojan-FCSU!DB81F2F8656B
MalwarebytesUrelas.Trojan.Downloader.DDS
ZillyaTrojan.Urelas.Win32.447
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 005890e71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36250.Uv3@a0r8qebO
VirITTrojan.Win32.AVKill.BLQJ
CyrenW32/Plite.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Urelas.AR
APEXMalicious
ClamAVWin.Trojan.R-102
KasperskyRootkit.Win32.Plite.pvf
BitDefenderTrojan.GenericKDZ.82870
NANO-AntivirusTrojan.Win32.Plite.crinlj
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.afj
EmsisoftTrojan.GenericKDZ.82870 (B)
BaiduWin32.Rootkit.Agent.s
F-SecureTrojan.TR/Urelas.zlvkz
DrWebTrojan.AVKill.25437
VIPRETrojan.GenericKDZ.82870
McAfee-GW-EditionBehavesLike.Win32.Trojan.tz
Trapminemalicious.high.ml.score
SophosTroj/Gupboot-C
IkarusTrojan.Win32.Gupboot
GDataWin32.Trojan.PSE.110RWKI
JiangminTrojan/Generic.aoxdt
GoogleDetected
AviraHEUR/AGEN.1314970
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.GupBoot.BFC@5szi8p
ArcabitTrojan.Generic.D143B6
ZoneAlarmRootkit.Win32.Plite.pvf
MicrosoftTrojan:Win32/Gupboot!atmnm
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gupboot.R290822
Acronissuspicious
VBA32Trojan.Packed
ALYacTrojan.GenericKDZ.82870
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.143703
RisingTrojan.Agent!1.9D23 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11769802.susgen
FortinetW32/Urelas.O!tr
AVGWin32:Malware-gen
Cybereasonmalicious.8656bb
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Gupboot!atmnm?

Trojan:Win32/Gupboot!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment