GuLoader: what it is and how to remove it
GuLoader is a type of malware that is used by the attackers to download and install other malicious software on the targeted machines, predominately Remote Access Trojans. Initially spotted in December 2019 by security researchers, the downloader was used by multiple different cybercriminal gangs to infect regular consumers and corporations with malware like NanoCore, Remcos, FormBook, NetWire, and many other RATs.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with GuLoader.
Do it yourself · free Remove GuLoader yourself 5 steps, about 15 minutes, no software needed.
Start the steps
GuLoader: summary
| Distribution | Malware was spotted in various malicious email campaigns but it can also be proliferated using other methods, such as fake updates, drive-by downloads, software cracks, exploit kits, etc. |
|---|---|
| Name | GuLoader |
| Type | Malware downloader |
| Targeted OS | Windows |
| Associated payloads | The downloader was used in multiple campaigns and installed malware like NanoCore, Remcos, FormBook, NetWire, Parallax, Agent Tesla, Warzone RAT, and many others |
| Symptoms | All the activities performed by GuLoader happen in the background, and no visible signs can be seen; once the malware is installed, users might spot some signs of infection, such as suspicious processes running in the background, system slowdowns/errors/crashes/lag, high CPU usage, etc. |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 6 more facts
| Implications | The downloaded malware can allow the attackers to control the machine remotely, meaning that they can steal sensitive information, install other malicious programs, steal users' or companies' funds, and perform other malicious activities |
|---|---|
| Detection names | No Microsoft detection name is known |
| Damage | Not recorded in the old report |
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 11 May 2020 |
| Facts checked | 7 October 2026 |
What GuLoader does on an infected PC
From our report of May 2020 · not reviewed since
GuLoader is a malware downloader associated with infiltration of Remote Access Trojans like Remcos
GuLoader is a type of malware that is used by the attackers to download and install other malicious software on the targeted machines, predominately Remote Access Trojans.
Initially spotted in December 2019 by security researchers, the downloader was used by multiple different cybercriminal gangs to infect regular consumers and corporations with malware like NanoCore, Remcos, FormBook, NetWire, and many other RATs.
While GuLoader itself is not used for malicious purposes such as information stealing, the tools that are proliferated via the downloader can perform a variety of tasks. Users infected with this malware can suffer considerable financial losses, loss of data, and even identity theft.
GuLoader is a portable executable that is typically stored inside a compressed file, such as an .ISO or a .RAR. Once clicked, it follows a particular behavioral pattern that downloads the malicious payload from a remote server - typically, OneDrive or Google Drive is used. Since the payload is encrypted with XOR algorithm, these platforms are unable to detect malware in the first place, allowing cybercriminals to operate the scheme easily.
In other words, while various companies and businesses often employ the Cloud system for large file storage space (backups are often held on the cloud, for example), threat actors behind the GuLoader virus also use it for malicious purposes.
GuLoader can be downloaded from a variety of sources, although multiple malspam campaigns were spotted employing it. Nonetheless, users might also get infected with malware via the following ways:
Once inside the system, GuLoader will contact a particular location on the cloud and download predetermined malware. As mentioned above, this downloader is typically used to install Remote Access Trojans, which are extremely dangerous. They allow the attackers to perform a variety of functions, such as stealing sensitive information (credit card details, passwords, email contents, etc.), downloading and installing files, taking screenshots, monitoring computer resources, etc.
Without a doubt, GuLoader can be the cause of the infection of multiple different malicious programs, that can all operate silently, performing malicious operations in the background. In case such malware like ransomware is installed, users can also lose access to all their files, such as work documents or personal pictures.
Malicious actors then demand to pay a ransom in Bitcoin or another cryptocurrency, and the amount can be relatively high. Even then, there is no guarantee that the promised decryptor is provided by the attackers.
What makes GuLoader removal and detection complicated is its obfuscation capabilities. It uses a variety of process injection techniques, such as spawning a child process of itself, overwriting the DLL image of the system, etc. Due to these sophisticated methods, analyzing of GuLoader is difficult. Unfortunately, but users are likely not to notice the malware in operation, as everything it does is performed silently in the background.
The best way to remove GuLoader, you will have to employ powerful anti-malware software and perform a full system scan. In case malware is tampering with security software, you can access Safe Mode with Networking (malware's operations are temporarily disabled in this mode, as the system is launched with only the most necessary drivers) as explained below. Additionally, after GuLoader malware elimination, you should also use to fix virus damage.
- Fake updates
- Drive-by downloads
- Software cracks
- Repacked installers
- Software vulnerabilities
- Exploits, etc.


From our report of May 2020 · not reviewed since
More from our earlier report on GuLoader
- To eliminate the downloader and the payload safely, perform a full system scan with anti-malware tools like
- Malware can cause significant damage to system files.
- If you spotted you computer lagging, crashing, returning errors, you should repair the virus damage with
How to remove GuLoader
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like GuLoader add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after GuLoader, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of GuLoader that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
GuLoader can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
From our report of May 2020 · not reviewed since
Prevent the infiltration of malicious software by being attentive online
As evident, there is a multitude of methods that malicious actors use to deliver malware to as many users as possible.
Despite the popular belief, however, malware does not simply access the machine out of nowhere - its infiltration point can often be traced back to actions that users made, either intentionally or not. There are several attack vectors that we would like to discuss - we will also explain how to reduce the probability of the infection to a minimum.
- Spam email attachments are possibly one of the most common malware delivery methods used by cybercriminals. While some phishing emails can be targeted (attack a particular individual or a company of interest), crooks typically employ botnets and other spam tools to ensure that thousands of users receive the fake message in their inboxes. Luckily, many such emails end up in spam boxes, although some still manage to break in. Thus, never all a macro to be run via MS Office documents, as it begins the infection chain immediately. Also, do not click on embedded links, even if they look as legitimate banners or buttons.
- To prevent the automatic installation of malware, you need to ensure that your system is running on the latest patch. For that, enable automatic updates on Windows. Do not forget to do the same with all the applications you have installed on the PC, as they can also be laced with vulnerabilities that the attackers can exploit.
- Practice good browsing habits - do not click on suspicious ads or visit high-risk websites. In most cases, users are aware that sites like torrents that host pirated programs/software cracks are riddled with malware, but they are still willing to risk it. What makes it worse, that some of the installers might install the anticipated program along with malware that will be running in the background, out of sight of the user.
- Equip your computer with powerful security software that can prevent the infiltration of malware in the first place. While there is no anti-malware tool that could protect from all malicious programs (malware is constantly evolving and using various obfuscation techniques), you can be sure that it will increase the security of your machine exponentially.
From our report of May 2020 · not reviewed since
Eliminate GuLoader along with other malware installed on the device
As evident, the main goal of the GuLoader virus is to download and install other malware, such as RATs or info-stealers.
These malicious programs can be extremely dangerous, as they can steal sensitive data without users' knowledge, turn the machine into a spam bot, or even completely corrupt the operating system. In other words, Remote Access Tools enable the attackers to perform any actions they want on a hijacked machine. That is why a timely GuLoader removal is so important.
However, if you remove GuLoader manually, malicious programs that were installed by it will remain on the system. Therefore, you should employ powerful anti-malware solutions and perform a full system scan.
Since malware injected by the virus can be deceptive and advanced, it might also attempt to disable your security software. In such a case, you should access Safe Mode with Networking and perform a full system from there. This will temporarily render malware useless, allowing it to get eliminated without problems.
After you are completely sure that you got rid of GuLoader and all the other malware on your system, you should also change all your passwords and monitor your online banking activities. If you are aware that your banking credentials were accessed, you should contact your bank and disable the account immediately.
[GI=method-1]In case GuLoader malware is preventing its termination, access Safe Mode with Networking:
After removal: passwords, accounts and prevention
Secure your accounts after the clean-up
Assume that whatever was saved in the browsers on this PC while the PC showed guLoader in the list of installed apps has been copied:
- passwords
- cookies
- autofill data
Work from a clean device, or from this PC once the offline scan finds nothing.
Start with your main e-mail account, because it can reset everything else, then banking and payment, then social and gaming accounts. Change each password, sign out of all sessions and turn on two-step verification: Turn on two-step verification / secure a hacked account.
The full order, including crypto wallets and card replacement, is in securing your accounts after malware.
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
Questions about GuLoader
Is GuLoader a virus?
Most programs that appear the way GuLoader did are not viruses in the strict sense. They are potentially unwanted programs:
- real software that arrives bundled with other downloads and then shows offers
- changes browser settings
- starts with Windows
Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.
Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.
How do I stop programs like GuLoader from being installed again?
Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.
Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped GuLoader before it reached the app list.
I found AnyDesk or ScreenConnect that I did not install. Is that GuLoader?
Not necessarily GuLoader, but it is a warning sign. These are legitimate remote support tools, and criminals use them as ready-made backdoors, especially after tech support scams or fake invoice calls.
If you did not install it and no one you trust set it up, uninstall it, change passwords from a clean device and check your bank account. If someone connected to your PC through it, follow the steps for remote access trojans and consider a Windows reset. Installed apps sorted by date shows when it appeared.
Is GuLoader a known trojan?
Not as a documented family, at least not yet. What is known is the visible sign, guLoader in the list of installed apps, which matches a hidden program working for someone else.
New threats are often seen by victims weeks before researchers publish anything about them. Treat GuLoader as you would any trojan:
- remove what starts it
- run an offline scan
- change passwords from another device
If a scan reports a detection name, keep it; it usually reveals the family and whether it is known to download other malware. We update this guide when an analysis appears.
How dangerous is GuLoader?
Treat it as serious until proven otherwise. The visible sign is guLoader in the list of installed apps, and programs that behave this way often have more abilities than they show:
- copying passwords
- downloading other malware
- giving remote access
Its family is not known yet, so nobody can say which of these it uses. The good news is that the response is the same in every case and takes about an hour:
- cut the network
- remove the startup entry
- run an offline scan
- change passwords from a clean device
If someone had remote control, a full reset is safer.
Should I check my other computers too?
Yes, it takes little time and removes doubt. GuLoader itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.
Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.
My antivirus was on. How did a trojan get past it?
Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.
Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.
Do I need to reinstall Windows to get rid of GuLoader?
Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see guLoader in the list of installed apps again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.
Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.
Should I report GuLoader?
Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.
You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.
Will Fortect remove GuLoader?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For GuLoader, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- PaloAlto: GuLoader: Malspam Campaign Installing NetWire RAT (read October 7, 2026)
- Wikipedia: Vulnerability (computing) (read October 7, 2026)
- Proofpoint: GuLoader: A Popular New VB6 Downloader that Abuses Cloud Services (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)