Trojan

Trojan:Win32/Guloader.CA!MTB removal tips

Malware Removal

The Trojan:Win32/Guloader.CA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guloader.CA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Guloader.CA!MTB?


File Info:

name: 9A5A31D8C50D3028B6E8.mlw
path: /opt/CAPEv2/storage/binaries/8e9cb19ed03a5ad047bbc39fdb66314ee2c0a86568ac0ca9f254cbe31c5908f6
crc32: 22D91C38
md5: 9a5a31d8c50d3028b6e86d05845c2c82
sha1: dee09bbcae69a33f83d255784ee8e5389f7f80f2
sha256: 8e9cb19ed03a5ad047bbc39fdb66314ee2c0a86568ac0ca9f254cbe31c5908f6
sha512: 2caf42bccac5667ad840ef87b336e6965b8f87e62ccbe850b8231038cf22c72ad8c6c87f266c4abad33c733b30bae3f2ccd6cd1f0be153362a996b2590784f49
ssdeep: 24576:VV2+E+Q1yYkvDSwcszaPFbl9uO4ZhI+pDQ5aMwmFVdoZU:1akOwcssTQrHX0W6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11855E0D9900284A8CC1948B66425E7345732FE69843CDB8B7EDCBDBB7DB3249643DB81
sha3_384: 3302a058c70e81cbfc3ccf324e24808910e1ace28c78fedf084072bb609c89d0a4cbb0d36d53fb84e46aeb759ceaa159
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-12-15 22:24:32

Version Info:

Comments: Encephalograms Overtrimmed
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan:Win32/Guloader.CA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Makoob.4!c
MicroWorld-eScanTrojan.Generic.34026341
FireEyeTrojan.Generic.34026341
ALYacTrojan.Generic.34026341
MalwarebytesTrojan.GuLoader
ZillyaTrojan.Makoob.Win32.874
SangforTrojan.Win32.Injector.Vb3i
K7AntiVirusTrojan ( 005903451 )
AlibabaTrojan:Win32/Makoob.a7630273
K7GWTrojan ( 005903451 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.GenusT.DOHS
CyrenW32/Injector.XTHV-6852
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Injector.ASH
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Makoob.gen
BitDefenderTrojan.Generic.34026341
NANO-AntivirusTrojan.Win32.Makoob.jxunzr
AvastNSIS:InjectorX-gen [Trj]
TencentWin32.Trojan.FalseSign.Xdkl
SophosMal/Generic-S
F-SecureTrojan.TR/Injector.jullb
DrWebTrojan.Loader.1618
VIPRETrojan.Generic.34026341
TrendMicroTrojan.Win32.GULOADER.YXDGSZ
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Generic.34026341 (B)
GDataTrojan.Generic.34026341
WebrootW32.Trojan.Gen
AviraTR/Injector.jullb
ArcabitTrojan.Generic.D2073365
ZoneAlarmHEUR:Trojan.Win32.Makoob.gen
MicrosoftTrojan:Win32/Guloader.CA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.GuLoader.R592166
McAfeeArtemis!9A5A31D8C50D
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.GULOADER.YXDGSZ
YandexTrojan.Igent.b0ut7Q.1
IkarusTrojan.NSIS.Agent
FortinetNSIS/Injector.67B7!tr
AVGNSIS:InjectorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Guloader.CA!MTB?

Trojan:Win32/Guloader.CA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment