Trojan

Trojan:Win32/Guildma!pz removal tips

Malware Removal

The Trojan:Win32/Guildma!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guildma!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Guildma!pz?


File Info:

name: 0EB340A0430C5619DEAB.mlw
path: /opt/CAPEv2/storage/binaries/46c443a36ec241ab17c42ed68dba1e9cffc8f9a3a4b0be196e933537b883dbec
crc32: 34980A8F
md5: 0eb340a0430c5619deabaafe433f7fa1
sha1: 2976d1aa1018a68af5cb7939623e452e58f9a711
sha256: 46c443a36ec241ab17c42ed68dba1e9cffc8f9a3a4b0be196e933537b883dbec
sha512: 244f2097e5e56c4e2d65b6cacc584ed075236ef072e4c9c904365cbd6c46b7ce15505949cee0aeaf9b1d5ee9e9ed23101d293d7bda387d2835f7365dd3682e3f
ssdeep: 12288:6GwF8DRXgVPqaoXNoEixlbjDm+3z2AioLDl164NkCadduChtCgzF/gTj0boaFedu:XzXKqa8SEijjC+37iYi4daL5htCgzF/L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180E4C06FB34517B2C28203B23A0B99C7F72E9479237E85E06468801D2357E6C93BB7D5
sha3_384: 3cca21a954e272ea38f893e7cceb605962f58707c74bf34ef1f5c505fb9d79a26eb6b1e2f3a807b6407acd65646c5818
ep_bytes: e9e9c10200617f32a7a36d6016126d22
timestamp: 1991-02-05 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Guildma!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanDropped:Generic.Dacic.E9082EE5.A.A50BD2AA
FireEyeGeneric.mg.0eb340a0430c5619
SkyhighBehavesLike.Win32.Generic.jc
ALYacDropped:Generic.Dacic.E9082EE5.A.A50BD2AA
Cylanceunsafe
VIPREDropped:Generic.Dacic.E9082EE5.A.A50BD2AA
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderDropped:Generic.Dacic.E9082EE5.A.A50BD2AA
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.a1018a
BitDefenderThetaAI:Packer.73D2AAB01F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.WV
APEXMalicious
ClamAVWin.Malware.Vmprotect-9878304-0
KasperskyHEUR:Trojan.Win32.Convagent.gen
AlibabaTrojan:Win32/Guildma.933d10e6
RisingTrojan.Convagent!8.12323 (CLOUD)
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.tkztn
ZillyaTrojan.VMProtect.Win32.51894
TrendMicroTROJ_GEN.R002C0DK423
Trapminemalicious.high.ml.score
EmsisoftDropped:Generic.Dacic.E9082EE5.A.A50BD2AA (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Kryptik.spo
VaristW32/Trojan.YMKQ-2845
AviraTR/Redcap.tkztn
MAXmalware (ai score=88)
Antiy-AVLTrojan[Packed]/Win32.VMProtect
Kingsoftmalware.kb.b.997
MicrosoftTrojan:Win32/Guildma!pz
ArcabitGeneric.Dacic.E9082EE5.A.A50BD2AA
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
GDataWin32.Trojan.PSE.11X0MEY
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4541148
VBA32TScope.Trojan.Delf
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
Tencent Trojan.Win32.Agent.kf
YandexTrojan.VMProtect!s52oNh5Kupw
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtect.WV!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Guildma!pz?

Trojan:Win32/Guildma!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment