Trojan

How to remove “Trojan:Win32/Guildma.psyI!MTB”?

Malware Removal

The Trojan:Win32/Guildma.psyI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guildma.psyI!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Guildma.psyI!MTB?


File Info:

name: D89EB615433AE5F0901F.mlw
path: /opt/CAPEv2/storage/binaries/5da6adfebbd286ffe81d0f57df842daa5795e52a35f53b56d7807077c2ad88cd
crc32: 79E28D5F
md5: d89eb615433ae5f0901f71bfa73e0346
sha1: 031cb203dd63b11a562de3d2b952760e08b2e9cb
sha256: 5da6adfebbd286ffe81d0f57df842daa5795e52a35f53b56d7807077c2ad88cd
sha512: ac5050d9810db4fdf1a33df3f8e2020b1e4ebb6eefbfe64754a6a1f61963ca4eb587fbe135791c9bd475836cab58ba116f9ded0d36b88ca10c01e172ac3bb076
ssdeep: 12288:IjiMo7us39MQ4UWw4IS40caXN0UWuGrjottyI:IjiMkuEozwNTe1/yI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1A423D0759D9114E5454975F7A138AF61D2A29B80CC0BF893EEFFBBA8105C208E6F35
sha3_384: eedbe8f86067605ed6d56e0efdb76bf001499170fca82a9c3a30a93dfa576fb4d078188bd11bceebd92fdc792abb12b7
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Guildma.psyI!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GM.0500050802
FireEyeGeneric.mg.d89eb615433ae5f0
Cylanceunsafe
VIPREGen:Trojan.Heur.GM.0500050802
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.MultiPacked.BN
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.GM.0500050802
AvastWin32:Evo-gen [Trj]
SophosML/PE-A
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.GM.0500050802 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.GM.0500050802
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Packed]/Win32.MultiPacked
ArcabitTrojan.Heur.GM.D1DCE2B72
ZoneAlarmVHO:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Guildma.psyI!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Heur.C5469234
Acronissuspicious
BitDefenderThetaAI:Packer.8FBAD83B1D
ALYacGen:Trojan.Heur.GM.0500050802
MAXmalware (ai score=80)
VBA32Trojan.Downloader
RisingTrojan.Agent!8.B1E (TFE:5:6CPMShu4qpF)
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.5433ae
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Guildma.psyI!MTB?

Trojan:Win32/Guildma.psyI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment