Trojan

Trojan:Win32/Guloader.VAM!MTB malicious file

Malware Removal

The Trojan:Win32/Guloader.VAM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Guloader.VAM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Guloader.VAM!MTB?


File Info:

crc32: 02ADB3EB
md5: 946161b61a29736abd77ba4b613062b3
name: 946161B61A29736ABD77BA4B613062B3.mlw
sha1: bc6877bafe783b155b1c605bd2a91bb9c38caf0c
sha256: 4edcf51bd395ac3d0d14145367d496052f4059650a45a8ed49fa578245011f88
sha512: 4da6f98e4a93b00bb6fbebd86b75bf5fb9b5ec42947143956f370b16b7dd4076d248e95f25fb36b680820e0268c1772a22b572bf90e216a17184116ae4c32577
ssdeep: 768:H0zTSNpG3AZyRu0HC3/viVWoxR8FlIRkHhJXZzdNPu1gxcPr5dz3ZO04WEI:LKAt/v4DkFlIKH/bNPu1QcPr5VJREI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Affecters9
FileVersion: 2.01
CompanyName: ARM. Limited
Comments: ARM. Limited
ProductName: Gummiged
ProductVersion: 2.01
OriginalFilename: Affecters9.exe

Trojan:Win32/Guloader.VAM!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.812495
FireEyeGeneric.mg.946161b61a29736a
CAT-QuickHealTrojan.Multi
McAfeeRDN/GuLoader
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005752c11 )
BitDefenderGen:Variant.Razy.812495
K7GWTrojan ( 005752c11 )
CyrenW32/Trojan.BHSR-0701
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanDownloader.Agent.FEI
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.acwe
AlibabaTrojan:Win32/vbcrypt.ali2000008
ViRobotTrojan.Win32.Z.Razy.77824.AGL
RisingDownloader.Guloader!1.D089 (CLASSIC)
Ad-AwareGen:Variant.Razy.812495
EmsisoftGen:Variant.Razy.812495 (B)
DrWebTrojan.DownLoader36.30428
TrendMicroTrojanSpy.Win32.ARTEMIS.USMANLO20
McAfee-GW-EditionRDN/GuLoader
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Agent
JiangminTrojan.Vebzenpak.inn
KingsoftWin32.Troj.Vebzenpak.ac.(kcloud)
MicrosoftTrojan:Win32/Guloader.VAM!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Razy.DC65CF
AhnLab-V3Trojan/Win32.GuLoader.C4280974
ZoneAlarmTrojan.Win32.Vebzenpak.acwe
GDataGen:Variant.Razy.812495
CynetMalicious (score: 90)
VBA32TScope.Trojan.VB
ALYacTrojan.Agent.GuLoader
MAXmalware (ai score=87)
MalwarebytesTrojan.GuLoader
ZonerTrojan.Win32.100115
TrendMicro-HouseCallTrojanSpy.Win32.ARTEMIS.USMANLO20
TencentMalware.Win32.Gencirc.11b7fa7b
YandexTrojan.Igent.bU2Gjw.24
FortinetW32/Injector.EODF!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.a71

How to remove Trojan:Win32/Guloader.VAM!MTB?

Trojan:Win32/Guloader.VAM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment