Trojan

TrojanDropper:Win32/Gamarue.H removal

Malware Removal

The TrojanDropper:Win32/Gamarue.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Gamarue.H virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine TrojanDropper:Win32/Gamarue.H?


File Info:

name: 3CA91FF1ED79BD4CDAF5.mlw
path: /opt/CAPEv2/storage/binaries/1027c24674c108224868c24775f5881ab815e0634cf00ccfbbb05647a23eb17c
crc32: E1C8711A
md5: 3ca91ff1ed79bd4cdaf5532a034dc9e6
sha1: 43b3cf518bae90764108a04d77800322d889ca9b
sha256: 1027c24674c108224868c24775f5881ab815e0634cf00ccfbbb05647a23eb17c
sha512: a1116dd25a7dd9f8728527d99966b2a5016bea9331877c868e875ba533dbc10831d5d8d3726160d33e2c1b4f71fd4f403cf2b7ec1d4e1721ac8dcce4712543a0
ssdeep: 6144:j6XtlcqvOUFkvaBB+ViMtUkMFC5uNFdmopw:4cqPH04MGkMFCArmIw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D284E076FFD93C76C90301738497AD652364CEAA37518777DA410F8EF828390AD5BA22
sha3_384: 43b2d671ddb99a20bd1bd3ebf871402043bdb0d0d6b08c8f84f2a479d96bf43effd397a72ff6f8b21303a06b842a4400
ep_bytes: 558bec6aff68a060400068c836400064
timestamp: 2013-07-11 17:57:27

Version Info:

0: [No Data]

TrojanDropper:Win32/Gamarue.H also known as:

BkavW32.AIDetectMalware
ClamAVWin.Trojan.Agent-1274603
CAT-QuickHealTrojan.Mauvaise.S2505548
McAfeeGenericRXAA-AA!3CA91FF1ED79
Cylanceunsafe
VIPREGen:Variant.Graftor.103413
SangforTrojan.Win32.Agent.atgen
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Variant.Graftor.103413
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.18bae9
BaiduWin32.Trojan-Downloader.Wauchos.a
VirITBackdoor.Win32.Generic.ADHZ
SymantecPacked.Dromedan!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AJSL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Andromeda.ccgntg
MicroWorld-eScanGen:Variant.Graftor.103413
RisingWorm.Gamarue!1.A224 (CLASSIC)
EmsisoftGen:Variant.Graftor.103413 (B)
F-SecureBackdoor.BDS/Androm.abfkiua
DrWebBackDoor.Andromeda.178
ZillyaBackdoor.Androm.Win32.2105
TrendMicroWORM_GAMARUE.SMV
McAfee-GW-EditionBehavesLike.Win32.Worm.fm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3ca91ff1ed79bd4c
SophosMal/Inject-CEE
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Androm.vu
WebrootW32.Injector.Gen
AviraBDS/Androm.abfkiua
MAXmalware (ai score=86)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftTrojanDropper:Win32/Gamarue.H
XcitiumTrojWare.Win32.Injector.AKUJ@511j6o
ArcabitTrojan.Graftor.D193F5
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.103413
GoogleDetected
AhnLab-V3Backdoor/Win32.Androm.R79775
BitDefenderThetaGen:NN.ZexaF.36738.xqW@aahlIWcO
ALYacGen:Variant.Graftor.103413
TACHYONBackdoor/W32.Androm.380416
DeepInstinctMALICIOUS
VBA32SScope.Malware-Cryptor.Wauchos.2183
MalwarebytesMalware.AI.4253205380
PandaGeneric Malware
ZonerTrojan.Win32.34347
TrendMicro-HouseCallWORM_GAMARUE.SMV
TencentMalware.Win32.Gencirc.114f80b9
YandexTrojan.Agent!VReEJPg3e4o
IkarusTrojan-Dropper.Win32.Gamarue
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.AKSZ!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove TrojanDropper:Win32/Gamarue.H?

TrojanDropper:Win32/Gamarue.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment