Worm

About “Worm:Win32/Gamarue.AN” infection

Malware Removal

The Worm:Win32/Gamarue.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.AN virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Gamarue.AN?


File Info:

name: A28165B151A0637079D4.mlw
path: /opt/CAPEv2/storage/binaries/20a673b69a6303eb3f1b4ade3c9ee145c3babd427d03a652d92c35eb90fc8bb6
crc32: CF04DF1D
md5: a28165b151a0637079d43de17dbf48d0
sha1: 11183c2ecc3b4735c63ec5443e6e869cfded6556
sha256: 20a673b69a6303eb3f1b4ade3c9ee145c3babd427d03a652d92c35eb90fc8bb6
sha512: 6d13d2d9da79484dcd44b79116ab5cd2f32a643b63f67a42d3f5873c3007eb0a2548f81138fb5794b77188e8d8f2f9898ebd8f48fa66ce4f1ac883c57af8ff0c
ssdeep: 1536:02t2FTxKedWNbLaGepikKhiqHpBBTliYsk15fw92z/M/OE:12JxDdWNbLAiM0FnB15fv/kf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4E3AEF075C0C033C5956034446ACEF15EBEA8322675066B7B9DB7AF5F203E1573926A
sha3_384: 6725c711f367cacf06447daf53efa15e1b9f86410de0a75d552ad7dd9db876f88fd027b1407b8a528262e9ee3fbddaf1
ep_bytes: e8cd220000e979feffff8bff558bec81
timestamp: 2014-08-17 11:21:20

Version Info:

CompanyName: Google Inc.
FileDescription: Google Chrome
FileVersion: 20.0.1132.47
InternalName: chrome_exe
LegalCopyright: Copyright (C) 2006-2010 Google Inc. All Rights Reserved.
OriginalFilename: chrome.exe
ProductName: Google Chrome
ProductVersion: 20.0.1132.47
CompanyShortName: Google
ProductShortName: Chrome
LastChange: 144678
Official Build: 1
Translation: 0x0409 0x04b0

Worm:Win32/Gamarue.AN also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen.65341
MicroWorld-eScanTrojan.Agent.BFCC
FireEyeGeneric.mg.a28165b151a06370
CAT-QuickHealWorm.Gamarue.WR5
ALYacTrojan.Agent.BFCC
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.11080
K7AntiVirusTrojan-Downloader ( 0049c6041 )
K7GWTrojan-Downloader ( 0049c6041 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34084.iq0@aKaTiIgi
CyrenW32/Trojan.OLVM-2083
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Wauchos.AF
TrendMicro-HouseCallMal_Ispi-2
ClamAVWin.Trojan.Ranapama-9794859-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BFCC
NANO-AntivirusTrojan.Win32.Androm.delyyw
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Malware-gen
Ad-AwareTrojan.Agent.BFCC
EmsisoftTrojan.Agent.BFCC (B)
VIPRETrojan.Win32.Wauchos.afc (v)
SophosTroj/Faker-F
Ikarusnot-a-virus:AdWare.Win32.Gaba
GDataTrojan.Agent.BFCC
JiangminBackdoor.Androm.aqaq
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.BC7CE3
MicrosoftWorm:Win32/Gamarue.AN
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R117547
McAfeeGenericATG-FAIB!A28165B151A0
VBA32Backdoor.Androm
APEXMalicious
RisingBackdoor.Win32.Androm.ir (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.MMTR!tr
AVGWin32:Malware-gen
Cybereasonmalicious.151a06
PandaTrj/Downloader.WKY

How to remove Worm:Win32/Gamarue.AN?

Worm:Win32/Gamarue.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment