Worm

About “Worm:Win32/Gamarue.I” infection

Malware Removal

The Worm:Win32/Gamarue.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.I virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Worm:Win32/Gamarue.I?


File Info:

crc32: 45FBCD72
md5: daddab43cb1ba2b8b23499440906748f
name: bin.exe
sha1: 712dd29c6c9f85ccfe06aafc9e9197dc2674702e
sha256: 0ae0f118c5a13edc0d65a62886171bfafdab36315a6a977e58719f5528bd8094
sha512: 57e045078d53c57a92cb1bf3cacf105ac4120892e734b3f535e9065c46afc563207915ce1de4fe3698c7bafea281b48667969ac03e43953795aecd21df2922c9
ssdeep: 6144:Hl6IzB3TWLxa5BpKGUdRqRGCEmRWTftkLQC3d0pDs+OJ1yZXbwlRwh7x8m04Qz:cItWMB9Udj/Fk7N0Sjqbwlava
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.9.3.0
InternalName: Output.exe
FileVersion: 1.9.3.0
CompanyName: Telegram FZ-LLC
Comments: Telegram Desktop Setup
ProductName: Telegram Desktop
ProductVersion: 1.9.3.0
FileDescription: tsetup.1.9.3
OriginalFilename: Output.exe

Worm:Win32/Gamarue.I also known as:

FireEyeGeneric.mg.daddab43cb1ba2b8
SangforMalware
K7AntiVirusTrojan ( 0055f47d1 )
K7GWTrojan ( 0055f47d1 )
Cybereasonmalicious.c6c9f8
TrendMicroTROJ_FRS.VSNW14A20
BitDefenderThetaGen:NN.ZemsilF.34084.Dm2@aynPkVc
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Gamarue.drycn
Invinceaheuristic
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
AviraTR/AD.Gamarue.drycn
Endgamemalicious (moderate confidence)
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftWorm:Win32/Gamarue.I
AhnLab-V3Malware/Win32.RL_Generic.C3940095
McAfeeArtemis!DADDAB43CB1B
ESET-NOD32a variant of MSIL/Kryptik.UJE
TrendMicro-HouseCallTROJ_FRS.VSNW14A20
TencentWin32.Trojan.Falsesign.Wvaz
eGambitPE.Heur.InvalidSig
FortinetMSIL/Androm.UJE!tr.bdr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Gamarue.I?

Worm:Win32/Gamarue.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment