Threat Database Trojans Trojan.Glupteba.G

Trojan.Glupteba.G

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,284
Threat Level: 80 % (High)
Infected Computers: 429
First Seen: June 10, 2021
Last Seen: June 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Glupteba.G on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your system's integrity and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Glupteba.G?

Trojan.Glupteba.G is a type of malware that can infiltrate your system without your knowledge or consent. The name itself does not provide specific information about the malware family, but it is clear that it is a Trojan-type threat. Trojans are malicious programs that can disguise themselves as legitimate software, allowing them to evade detection and gain unauthorized access to your system. Once inside, they can cause significant damage, including data theft, system crashes, and unauthorized access to your personal information.

How Trojan.Glupteba.G Operates

Although the exact mechanisms of Trojan.Glupteba.G are not specified, Trojans typically operate by exploiting vulnerabilities in your system or tricking you into installing them. They can be spread through various means, including infected software downloads, phishing emails, or compromised websites. Once installed, Trojans can communicate with their command and control servers, allowing them to receive instructions and transmit stolen data. They can also install additional malware, create backdoors, and disrupt system operations.

Symptoms of Infection

The symptoms of a Trojan.Glupteba.G infection can vary, but common indicators include slow system performance, frequent crashes, and unexplained changes to your system settings. You may also notice unusual network activity, such as unfamiliar programs accessing the internet or strange login attempts. Additionally, you may receive alerts from your security software or notice that your antivirus program is disabled or compromised. If you suspect that your system is infected, it is crucial to take immediate action to contain and remove the threat.

How to Remove Trojan.Glupteba.G

  1. Boot your system in Safe Mode with Networking to prevent the Trojan from loading and to allow your security software to run more effectively.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the Trojan.
  3. Uninstall any suspicious programs or software that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that the Trojan has been completely removed and that your system is clean.

Conclusion

The detection of Trojan.Glupteba.G is a serious security alert that requires prompt attention. By understanding the nature of this threat and taking the necessary steps to remove it, you can protect your system and personal data from further harm. Remember to always be cautious when downloading software or clicking on links, and keep your security software up to date to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the help of a professional or contacting a reputable security vendor for guidance.

Analysis Report

General information

Family Name: Trojan.Glupteba.G
Signature status: No Signature

Known Samples

MD5: d5e4b21d43e758edac543af874ade4af
SHA1: 4a747bc7bc9457f3b150d6f51c1d51f3de0f5ebf
SHA256: 4B78FA36FDD1EC420FA0ECB804062E2748CD214E2DE3387B25617E78B9547C79
File Size: 275.46 KB, 275456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,189
Potentially Malicious Blocks: 13
Whitelisted Blocks: 1,176
Unknown Blocks: 0

Visual Map

x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 1 0 0 2 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 3 0 0 2 2 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\tfelmtp.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ud.tfelmtp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Kwligste\AppData\Local\Temp\tFeLmTp.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Kwligste\AppData\Local\Temp\tFeLmTp.exe\??\C:\Users\Kwligste\AppData\Local\Temp\ud.tFeLmTp RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Kwligste\AppData\Local\Temp\tFeLmTp.exe C:\Users\Kwligste\AppData\Local\Temp\tFeLmTp.exe "c:\users\user\downloads" C:\Users\Kwligste\AppData\Local\Temp\ud.tFeLmTp

Trending

Most Viewed

Loading...