Trojan

Should I remove “Trojan:Win32/Gamarue!atmnm”?

Malware Removal

The Trojan:Win32/Gamarue!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gamarue!atmnm virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Gamarue!atmnm?


File Info:

name: AEE589E333C719A52D47.mlw
path: /opt/CAPEv2/storage/binaries/067819e13b430681fd85297380f299cbadafc4c769c4a8ac9d420c3c46597e40
crc32: B6852175
md5: aee589e333c719a52d4733409c737d0e
sha1: 72dabd862453a4db65d59c109f4e59e8d10660c5
sha256: 067819e13b430681fd85297380f299cbadafc4c769c4a8ac9d420c3c46597e40
sha512: 070138c39c2b48a14a2389c941a60e7cee0673233f301a0decd213e36e6d8b39aae0da3256276ff8545453aaf705752f5662605fb846457cca65525966737655
ssdeep: 1536:t4BB+DF5YTOrzxTe2EchmW3vJ9cEiAM+RAy/:tkB+UTaTN3mWhZiAM+RAc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A934A107A51C473E0A2293445BAC7F24BBE793217B884C77B9816BE5FB13C2573639A
sha3_384: a788dca135fc7f007e21dc1debaafd58d88732291ab0e23e184e07b007e204afc9898099c0f28715973bc0dfc8f39037
ep_bytes: e899440000e989feffff8bff558bec81
timestamp: 2015-11-09 04:47:42

Version Info:

0: [No Data]

Trojan:Win32/Gamarue!atmnm also known as:

LionicTrojan.Win32.ChompStays.4!c
MicroWorld-eScanGeneric.Dacic.06B5CF0E.A.DA786C89
ClamAVWin.Malware.Generickdz-9775453-0
FireEyeGeneric.mg.aee589e333c719a5
CAT-QuickHealTrojan.GenericPMF.S30085441
McAfeeGenericRXCC-BN!AEE589E333C7
MalwarebytesMalware.AI.1044283777
VIPREGen:Variant.Midie.99116
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005a56bc1 )
K7GWTrojan ( 005a56bc1 )
Cybereasonmalicious.333c71
CyrenW32/Agent.FRZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Andariel.I
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.ChompStays.gen
BitDefenderGeneric.Dacic.06B5CF0E.A.DA786C89
NANO-AntivirusTrojan.Win32.ChompStays.jvjoih
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10be6eb6
SophosMal/Agent-ARR
F-SecureHeuristic.HEUR/AGEN.1362155
DrWebTrojan.DownLoader45.48603
ZillyaTrojan.Andariel.Win32.190
McAfee-GW-EditionBehavesLike.Win32.Generic.nt
EmsisoftGeneric.Dacic.06B5CF0E.A.DA786C89 (B)
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1R5N4UM
JiangminTrojan.ChompStays.ab
AviraHEUR/AGEN.1362155
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.ChompStays
XcitiumTrojWare.Win32.Agent.SBXK@7g63mg
ArcabitGeneric.Dacic.06B5CF0E.A.DA786C89
ZoneAlarmHEUR:Trojan.Win32.ChompStays.gen
MicrosoftTrojan:Win32/Gamarue!atmnm
GoogleDetected
AhnLab-V3Win-Trojan/Rifdoor.Gen
BitDefenderThetaGen:NN.ZexaF.36250.fuX@amArsqd
ALYacGen:Variant.Midie.99116
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.Agent!8.B1E (TFE:5:9p6zG1u7F3N)
YandexTrojan.GenAsa!FG4K9HJM8Ec
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.UDW!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Gamarue!atmnm?

Trojan:Win32/Gamarue!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment