Trojan

Trojan:Win32/GuLoader.PDH!MTB information

Malware Removal

The Trojan:Win32/GuLoader.PDH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GuLoader.PDH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/GuLoader.PDH!MTB?


File Info:

crc32: 8DDDA228
md5: 89fa80828ad2a5e394479837032583cf
name: 89FA80828AD2A5E394479837032583CF.mlw
sha1: d5a749eff7436531217701ba60702231503cd297
sha256: 114a916b9bce9f2e243f94be846267cd0a84516fc40c05b7eb39d4210b6e7ad1
sha512: 29c7c7da0b0c6d4cbe8e1554b0f49c078ab7f36900c302458bd64146e940ea4dc21413ba653bd25cb30d6286561b4a95e10df1624669bebf731f4487ef8f4f1b
ssdeep: 3072:SeWCA4PPXuSbje3wlxBbaVuc29lw9eNWBGf/iZxEOMIDdBr2C:JuSb2wf8upAB+/qJMOdB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Overlint
InternalName: Transportbaandet8
FileVersion: 3.04.0005
CompanyName: Overlint
LegalTrademarks: Overlint
Comments: VBNULLSTING
ProductName: Overlint
ProductVersion: 3.04.0005
FileDescription: Overlint
OriginalFilename: Transportbaandet8.exe

Trojan:Win32/GuLoader.PDH!MTB also known as:

K7AntiVirusTrojan ( 0058a7991 )
LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.2385
CynetMalicious (score: 99)
CAT-QuickHealTrojanspy.Noon
ALYacGen:Variant.Midie.103938
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/GuLoader.62d47eea
K7GWTrojan ( 0058a7991 )
CyrenW32/VBKrypt.BDN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNNV
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Midie-9910637-0
KasperskyTrojan-Spy.Win32.Noon.bcjj
BitDefenderGen:Variant.Midie.103938
MicroWorld-eScanGen:Variant.Midie.103938
TencentWin32.Trojan.Midie.Eerq
Ad-AwareGen:Variant.Midie.103938
SophosMal/Generic-R + Troj/Zbot-POJ
BitDefenderThetaAI:Packer.EB8C484D20
TrendMicroTrojanSpy.Win32.WACAPEW.USMANKH21
McAfee-GW-EditionRDN/Generic PWS.y
FireEyeGeneric.mg.89fa80828ad2a5e3
EmsisoftGen:Variant.Midie.103938 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Nekark.rluer
MicrosoftTrojan:Win32/GuLoader.PDH!MTB
GDataGen:Variant.Midie.103938
AhnLab-V3Malware/Gen.Generic.R450549
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=85)
VBA32TrojanSpy.Noon
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.WACAPEW.USMANKH21
YandexTrojan.AvsArher.bTx33N
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FNNV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/GuLoader.PDH!MTB?

Trojan:Win32/GuLoader.PDH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment