Malware

W32/Gamarue-BM malicious file

Malware Removal

The W32/Gamarue-BM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Gamarue-BM virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine W32/Gamarue-BM?


File Info:

name: E40FEC93972CCB924324.mlw
path: /opt/CAPEv2/storage/binaries/bc864e75e938bdda7fbdb6a017d63b892c4b2a3206133ab93d02cc3509d5e0c9
crc32: 3FAA61FB
md5: e40fec93972ccb924324d4cc070c2d00
sha1: 89ba63724c1e7bf6229fbf30852f15869cc58fb6
sha256: bc864e75e938bdda7fbdb6a017d63b892c4b2a3206133ab93d02cc3509d5e0c9
sha512: bbfc03b0040f391e39052cd52faf62c65bb6b8c795c3e9e0bf55fe981f1b827b5f69319c62287d36dcc0ab678a4471e154f005c449cda841bd0027484583d1a9
ssdeep: 48:SWkO0IoyTnXz+ihZjokkyH2mviaJ5dt5eFJHQdSDYlJ5O1:ZJTnXzvokwaJ5VqMSeO1
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19CA14A37B3B46A33E02487332F6745C77C395BA40368078B8A723147101501B9CA9F2B
sha3_384: 099b89fc9bd5d0dce97cff2c4674051e6dcd7732d3ffce06882cf1372c53d976ead62e0f6f4f31d206531d85ebb6e5a6
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-04-07 20:00:59

Version Info:

0: [No Data]

W32/Gamarue-BM also known as:

BkavW32.FamVT.DebrisB.Worm
LionicWorm.Win32.Debris.mrOd
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.e40fec93972ccb92
CAT-QuickHealTrojan.Agent.WL
ALYacGen:Variant.Barys.431082
Cylanceunsafe
VIPREGen:Variant.Barys.431082
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/Debris.f564a81c
K7GWEmailWorm ( 0040f50c1 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BaiduWin32.Worm.Bundpil.ah
VirITTrojan.Win32.Small.FAU
SymantecTrojan.Dropper
ESET-NOD32Win32/Bundpil.T
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Drop.bqqvjw
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
TencentTrojan.Win32.Csyr.A
EmsisoftGen:Variant.Barys.431082 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.MulDrop4.25343
ZillyaWorm.Bundpil.Win32.1334
Trapminesuspicious.low.ml.score
SophosW32/Gamarue-BM
IkarusWorm.Debris
JiangminWorm/Generic.aftt
GoogleDetected
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.Csyr
Kingsoftmalware.kb.a.976
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Barys.D693EA
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Trojan.PSE.1Y5UO7M
VaristW32/Csyr.A!Eldorado
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aejr6Qm
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32Worm.Gamarue
MalwarebytesBundpil.Worm.AutoRun.DDS
TrendMicro-HouseCallWORM_GAMARUE.SMB
RisingWorm.Bundpil!1.E3E2 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!worm
PandaTrj/Genetic.gen
alibabacloudWorm:Win/Bundpil.T

How to remove W32/Gamarue-BM?

W32/Gamarue-BM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment