Trojan

Trojan.GuLoader.Generic (file analysis)

Malware Removal

The Trojan.GuLoader.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GuLoader.Generic virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan.GuLoader.Generic?


File Info:

name: 4822C1DAD8550BF44255.mlw
path: /opt/CAPEv2/storage/binaries/91090321465550cf7089cfe6a708ab130381a9cdfcd6a8487c36c7a3715300c6
crc32: AFC84F40
md5: 4822c1dad8550bf442556475605043aa
sha1: a68410f1d0e5c678d23d773db115ef4ddfdad6df
sha256: 91090321465550cf7089cfe6a708ab130381a9cdfcd6a8487c36c7a3715300c6
sha512: 0294d63c3d1bb7b06dcac7cbdd6bdfd6c010f6be78ae328eb162f268df41ca869ada4845aa09fd3f42512f3389e4fc65975eeba5a58d06e43ce89f7aba389705
ssdeep: 3072:wfY/TU9fE9PEtuqOj6+Gp5WDSuDB4gbOk4PWZnR/HvPcvEj:GYa6zlmkDZ7KQRfcvEj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EF3AE1D3661C0E7F88D83706B369B0B2A9E7C132142151737B1B7B86B39693D90FAD9
sha3_384: 5468555eb7f386fe1af9f9a6185df8538f370b1584b888055b0fac471710ed08508837986433c64f71f291e881862e08
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

0: [No Data]

Trojan.GuLoader.Generic also known as:

Elasticmalicious (moderate confidence)
Paloaltogeneric.ml
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
IkarusWin32.Outbreak
GDataGen:Variant.Nemesis.9754
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
CynetMalicious (score: 100)
McAfeeArtemis!4822C1DAD855
MalwarebytesTrojan.GuLoader.Generic
PandaTrj/RnkBend.A

How to remove Trojan.GuLoader.Generic?

Trojan.GuLoader.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment