Trojan

Should I remove “Trojan:Win32/Guildma.psyU!MTB”?

Malware Removal

The Trojan:Win32/Guildma.psyU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guildma.psyU!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Guildma.psyU!MTB?


File Info:

name: 12637B24666BA420D206.mlw
path: /opt/CAPEv2/storage/binaries/6db17b7d0a2cd2e12f70c1ada46d61207afeaf1a827e5135502f4b1df435a617
crc32: 1FBBFA7F
md5: 12637b24666ba420d2067bbc83082420
sha1: 7f97a765e32ce2a5b13b4fc2e05dba70e68d11cc
sha256: 6db17b7d0a2cd2e12f70c1ada46d61207afeaf1a827e5135502f4b1df435a617
sha512: 8b4656394819c9b9b76e965c8d6b7be021addc52a5955e0b6408fdf412408ca1d6a6bfd69e82212d00c7ae160f78be090d5fdaa01afb9e0749e5aa048ef764dd
ssdeep: 96:nU4Nq5kWKBK4aVSTmtdYjuAAN42DxIVAeBZhoNjyUjSMUO:UHkr4ITcYjuAAiVAeeV5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144F141352FDB1EF2E377DAF389F2E7D5A675F572A627C24D80DA0B440503A819810E19
sha3_384: 35c6f37ca0f15b18d9ce736d01c02510e4a2595dc45385cccace5dcfb17e27249e2befff9271dd9320ee27695aba2964
ep_bytes: 558becb83c200000e873030000535657
timestamp: 2013-09-09 15:33:47

Version Info:

0: [No Data]

Trojan:Win32/Guildma.psyU!MTB also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.12637b24666ba420
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ppatre.Gen.1
Cylanceunsafe
ZillyaDownloader.Waski.Win32.2493
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0050fef41 )
K7GWTrojan-Downloader ( 004eadfb1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ppatre.Gen.1
BitDefenderThetaGen:NN.ZexaE.36308.amX@aaM70Me
VirITTrojan.Win32.Generic.BMBK
CyrenW32/S-79ee1585!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Downloader.Upatre-6723030-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.cjerhf
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-WID [Trj]
TencentTrojan-Downloader.Win32.Small.16000476
EmsisoftTrojan.Ppatre.Gen.1 (B)
BaiduWin32.Trojan-Downloader.Waski.k
DrWebTrojan.DownLoader45.3848
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_DLOADER.SM3
McAfee-GW-EditionBehavesLike.Win32.Downloader.zz
Trapminemalicious.high.ml.score
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.acusk
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
MicrosoftTrojan:Win32/Guildma.psyU!MTB
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R83549
McAfeeUpatre-FACV!12637B24666B
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
MalwarebytesSmall.Trojan.Downloader.DDS
TrendMicro-HouseCallTROJ_DLOADER.SM3
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Tiny.NIV!tr
AVGWin32:Downloader-WID [Trj]
Cybereasonmalicious.4666ba
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Guildma.psyU!MTB?

Trojan:Win32/Guildma.psyU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment