Trojan

Should I remove “Trojan:Win32/Guloader.SPAV!MTB”?

Malware Removal

The Trojan:Win32/Guloader.SPAV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guloader.SPAV!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojan:Win32/Guloader.SPAV!MTB?


File Info:

name: 9EE15CB0E1C24B94C8C5.mlw
path: /opt/CAPEv2/storage/binaries/0edc80c315a65145aedcb2c1c47ab3457c9f377c408d8419f25382b68a28a7b8
crc32: 48FD85AA
md5: 9ee15cb0e1c24b94c8c58c0052796ebb
sha1: 3cb785da270b6e65b0dc2a90d855302ab06ded8c
sha256: 0edc80c315a65145aedcb2c1c47ab3457c9f377c408d8419f25382b68a28a7b8
sha512: 0bdd04eb6450ec1a80b029a218bfd355de853765371625bd445de8c9d64966a951d2b19beb8cc8fd635e84d43b6637c859bef87142557ee5a92f084ae6f70459
ssdeep: 6144:oT4DtvPZVheNA+ff0IhTxa7zP6tcKSWwFhftQdF3N566g:oTUnhe2ebFYDWofQdF3N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8A47CA239C975AFDC2F4674035FEAB21AB95CE07391496E4F40360D4C3664A80EEED7
sha3_384: d339f1d56da672da93b03f25b31112e484a33f6da9215bdefc32e05522e11a8646283a34ab7c1a50f0b45068a31b4944
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:45:20

Version Info:

Aditional Notes: ller reskompagnis
Comments: dubbins brudelysenes destabilization
InternalName: jacked prluderet.exe
LegalCopyright: unseamed
LegalTrademarks: skolebogs armand lithobioid
ProductName: udaandingernes datamatsyns pinaceae
Translation: 0x0409 0x04e4

Trojan:Win32/Guloader.SPAV!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.70505410
FireEyeTrojan.GenericKD.70505410
SkyhighArtemis
ALYacTrojan.GenericKD.70505410
Cylanceunsafe
SangforTrojan.Win32.Injector.Vlaf
K7AntiVirusTrojan ( 0059035d1 )
AlibabaTrojan:Win32/Guloader.b5bf83e9
K7GWTrojan ( 0059035d1 )
ArcabitTrojan.Generic.D433D3C2
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32NSIS/Injector.ASH
CynetMalicious (score: 100)
APEXMalicious
BitDefenderTrojan.GenericKD.70505410
AvastNSIS:InjectorX-gen [Trj]
EmsisoftTrojan.GenericKD.70505410 (B)
F-SecureTrojan.TR/Injector.wmvot
VIPRETrojan.GenericKD.70505410
TrendMicroTrojan.Win32.GULOADER.YXDKUZ
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.NSIS.Agent
VaristW32/Injector.KSMK-8960
AviraTR/Injector.wmvot
Kingsoftmalware.kb.a.715
MicrosoftTrojan:Win32/Guloader.SPAV!MTB
GDataTrojan.GenericKD.70505410
GoogleDetected
McAfeeArtemis!9EE15CB0E1C2
MAXmalware (ai score=88)
MalwarebytesTrojan.GuLoader
TrendMicro-HouseCallTrojan.Win32.GULOADER.YXDKUZ
YandexTrojan.Igent.b1fDKb.2
FortinetW32/ASH!tr
AVGNSIS:InjectorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Guloader.SPAV!MTB?

Trojan:Win32/Guloader.SPAV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment