Worm

Worm:Win32/Gamarue.DK!MTB removal

Malware Removal

The Worm:Win32/Gamarue.DK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.DK!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.DK!MTB?


File Info:

name: 0ED47BCBC059C5BFE6FC.mlw
path: /opt/CAPEv2/storage/binaries/9291641b44b812d35dbb17cb76f98e9a74613e9dd5702cf70b5fd69c956f3953
crc32: E76BC6D0
md5: 0ed47bcbc059c5bfe6fc2f1f4615b0d5
sha1: 286a8ba60dcb8d336a48739fb68a79bf3836e305
sha256: 9291641b44b812d35dbb17cb76f98e9a74613e9dd5702cf70b5fd69c956f3953
sha512: d6dc8d52bb05d6c007dbfde4a3b0bbb855341a501e0d2296a371cb38c1efd3242220c5a4b930e478ac048f11a5cadd2e9e322fbfd90b5502bcb0874f32dbd5d3
ssdeep: 24:e1GSYTe3Cee/0I/kPVCRVtc44MnXz+iM2u8kypgyXwVQwA3H4tROjDHcurfJFOi8:SWkO0IoyTnXz+ihZjokHcurBY3n/Dh6S
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D081A537B3B91D73D0689B732E6B70CB3D6D4B8413A8095AC9402717152A023CD79E92
sha3_384: 3f466278b2b57d47c22718a12ecc36b3fa728305e77a7b38a42ae4997c12ae887a9119f90564379657867df8930ce7f9
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-04-07 20:00:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.DK!MTB also known as:

BkavW32.FamVT.DebrisB.Worm
MicroWorld-eScanGen:Variant.Barys.431082
ClamAVWin.Adware.Downware-246
FireEyeGeneric.mg.0ed47bcbc059c5bf
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Downloader.zz
McAfeeDownloader-FKP!0ED47BCBC059
MalwarebytesWorm.Gamarue
ZillyaWorm.Bundpil.Win32.1334
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWEmailWorm ( 0040f50c1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aejr6Qm
VirITTrojan.Win32.Small.FAU
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.T
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Drop.bqqvjw
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Atraps-PZ [Trj]
RisingWorm.Bundpil!1.E3E2 (CLASSIC)
SophosW32/Gamarue-BM
BaiduWin32.Worm.Bundpil.ah
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.MulDrop4.25343
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SMB
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Barys.431082 (B)
IkarusWorm.Debris
GDataWin32.Trojan.PSE.1Y5UO7M
JiangminWorm/Generic.aftt
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.Csyr
Kingsoftmalware.kb.a.785
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Barys.D693EA
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.DK!MTB
VaristW32/Csyr.A!Eldorado
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_GAMARUE.SMB
TencentTrojan.Win32.Csyr.A
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic!worm
AVGWin32:Atraps-PZ [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.DK!MTB?

Worm:Win32/Gamarue.DK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment