Trojan.Guildma.D
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Threat Level: | 80 % (High) |
| Infected Computers: | 14 |
| First Seen: | May 8, 2023 |
| Last Seen: | February 18, 2026 |
| OS(es) Affected: | Windows |
Your system has been detected to have a threat known as Trojan.Guildma.D. This detection indicates that your computer is infected with a type of malicious software that can potentially harm your system and compromise your personal data. It is essential to take immediate action to remove this threat and prevent any further damage.
Table of Contents
What Is Trojan.Guildma.D?
Trojan.Guildma.D is a type of Trojan, which is a broad category of malware that can perform a variety of malicious functions. Trojans are often disguised as legitimate software, but they can allow unauthorized access to your system, steal sensitive information, or disrupt your computer's operation. The name "Trojan.Guildma.D" suggests that it may be related to other Trojans, but without more specific information, it's difficult to determine its exact nature or purpose.
How Trojan.Guildma.D Operates
Trojan.Guildma.D, like other Trojans, is likely designed to operate stealthily, avoiding detection by security software and system administrators. It may use various techniques to infect your system, such as exploiting vulnerabilities in software, disguising itself as a legitimate program, or being downloaded by other malware. Once installed, it can communicate with its creators, allowing them to control your system, steal data, or use your computer for malicious activities.
Trojans can also download and install additional malware, creating a complex and resilient threat that is difficult to eradicate. They may also modify system settings, registry entries, or files, making it challenging to detect and remove them.
Symptoms of Infection
Systems infected with Trojan.Guildma.D may exhibit a range of symptoms, including slow performance, frequent crashes, or unexpected behavior. You may notice that your system is running slowly, or that programs are taking longer to launch. You may also see unusual pop-ups, ads, or messages, or experience difficulties connecting to the internet. In some cases, you may not notice any symptoms at all, as the Trojan may be designed to operate silently.
- Unexplained changes to system settings or files
- Unusual network activity or connections
- Slow system performance or crashes
- Appearance of unexpected programs or icons
- Difficulty accessing certain websites or online services
How to Remove Trojan.Guildma.D
- Boot your system in Safe Mode with Networking to prevent the Trojan from loading and to allow your security software to run more effectively.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
- Uninstall any suspicious programs or applications that you do not recognize or that were installed recently.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
- Reboot your system and run another full scan with your anti-malware tool to ensure that all remnants of the Trojan have been removed.
Conclusion
Removing Trojan.Guildma.D from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above, you can help to ensure that your system is free from this malicious software and that your personal data is protected. Remember to always use reputable security software and to keep your operating system and applications up to date to prevent future infections.
It's also essential to practice safe computing habits, such as avoiding suspicious downloads, using strong passwords, and being cautious when clicking on links or opening email attachments. By taking these precautions, you can help to protect your system and your personal data from the ever-evolving threats of malware and cybercrime.
Analysis Report
General information
| Family Name: | Trojan.Guildma.D |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
deb59f750642b0d47bc55d85af5363dd
SHA1:
cfc78b5085675a8eae46414ec47acfd6a5d90998
SHA256:
059396D21EF197ABC4EABDD95A316EF0AA60E90D2F9BC54DE6366D081A6CD4E4
File Size:
4.02 MB, 4024832 bytes
|
|
MD5:
0cc8b23fa9009f45c25431c8ddb97abf
SHA1:
498b6debdeffd32031acd9dcf69f8ed30a6b604a
SHA256:
51FD1D7880ACC5BC2C55A8CDFB0694563CA9332510AE4C55460DA5E2B71013EA
File Size:
124.93 KB, 124928 bytes
|
|
MD5:
4420e980233c7c998e73c3d8af90c454
SHA1:
f16697ff0f5c56bc75ce6164b3e9bf886da370bc
SHA256:
42DD3563156A85D7D3D87F8692EAA365E61524C4A2CF81590D8761F0F8D78BAD
File Size:
8.83 MB, 8834048 bytes
|
|
MD5:
b961accb50211dee0cbfe57fb1ce7995
SHA1:
61e5ffb6f47959b83a65907ed1b4000aba23921c
SHA256:
1409DBC029336CFCF75F3CA5F1A8F9A16D5D10BBD4EE80398AC1D6F2DFA69F2F
File Size:
43.01 KB, 43008 bytes
|
|
MD5:
af7ffff2269084505887933b1b244770
SHA1:
ff80ead53c680d2201eafe5878203b4d12316755
SHA256:
A358E27F5174315FD69C7B58B4B455BF065BF602D04208BC5040904AC92488E8
File Size:
9.78 MB, 9777152 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have security information
- File has exports table
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- 2+ executable sections
- dll
- VirtualQueryEx
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 16,140 |
|---|---|
| Potentially Malicious Blocks: | 26 |
| Whitelisted Blocks: | 16,112 |
| Unknown Blocks: | 2 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Danabot.DI
- Delf.FC
- Delf.OF
- FotopApps.A
- Guildma.D
Show More
- Injector.XN
- KillMBR.XE
- Ousaban.C
- ShandaAdd.A
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Shell Execute |
|
| Anti Debug |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\cfc78b5085675a8eae46414ec47acfd6a5d90998_0004024832.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\498b6debdeffd32031acd9dcf69f8ed30a6b604a_0000124928.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f16697ff0f5c56bc75ce6164b3e9bf886da370bc_0008834048.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\61e5ffb6f47959b83a65907ed1b4000aba23921c_0000043008.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ff80ead53c680d2201eafe5878203b4d12316755_0009777152.,LiQMAxHB
|