Worm

About “Worm:Win32/Gamarue.N” infection

Malware Removal

The Worm:Win32/Gamarue.N is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.N virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.N?


File Info:

name: CC05828E5F434C5A2BD2.mlw
path: /opt/CAPEv2/storage/binaries/75bd5235e6e64ffe9393cba0a621383d5d97d0cfab335e7b0415529fbaebc9c3
crc32: 3EF16EFF
md5: cc05828e5f434c5a2bd2bdeec9cb8604
sha1: 8915f69e01386a25a294c096148fe77860f52591
sha256: 75bd5235e6e64ffe9393cba0a621383d5d97d0cfab335e7b0415529fbaebc9c3
sha512: 032472378291b69969a4906091e0a1cd0039f4913eac76ab197905694855a23d830f4a762b10118fb722281ce5412b18a93ca7dc1c0e5cf95ec38bd8321df0f7
ssdeep: 96:z0dpglt6eGE0w1bTie3TaI3T1yCqmgbcz2RrW3bTiEY3:/x0aTZTaAT1y5mgbczyWbT/Q
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T169D178198A3148C0EFE822FF285D685775AA5317FDF4692CA32454CC91D1C1F9EAF2B2
sha3_384: ac8e1c37d03e8ad94387a3fa3bfe6bd142b9a27354a66cc346908f07ef38395c3c6fd64796a1fdf6d154a9ce94585c5e
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-18 16:02:35

Version Info:

0: [No Data]

Worm:Win32/Gamarue.N also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mikey.113463
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xt
McAfeeDownloader-FOB!CC05828E5F43
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.27
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f5281 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aqW1l@n
VirITWorm.Win32.Generic.GTI
SymantecDownloader.Dromedan
ESET-NOD32Win32/Bundpil.AR
APEXMalicious
ClamAVWin.Worm.Gamarue-6803702-0
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Mikey.113463
NANO-AntivirusTrojan.Win32.Debris.bxoyqm
SUPERAntiSpywareTrojan.Agent/Gen-Debris
AvastWin32:Sg-I [Trj]
TencentWorm.Win32.Debris.c
TACHYONWorm/W32.Debris.6567
EmsisoftGen:Variant.Mikey.113463 (B)
BaiduWin32.Worm.Agent.ai
F-SecureWorm.WORM/Gamarue.noue
DrWebTrojan.MulDrop4.25343
VIPREGen:Variant.Mikey.113463
TrendMicroWORM_GAMARUE.SML
FireEyeGeneric.mg.cc05828e5f434c5a
SophosMal/Generic-S
IkarusWorm.Win32.Bundpil
GDataGen:Variant.Mikey.113463
JiangminWorm/Debris.g
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.noue
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.998
XcitiumWorm.Win32.Bundpil.AH@4yjufs
ArcabitTrojan.Mikey.D1BB37
ViRobotTrojan.Win32.Agent.6658.A
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.N
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R71709
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Mikey.113463
MAXmalware (ai score=83)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
YandexTrojan.GenAsa!XiPmYt8B92Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Debris.X!worm
AVGWin32:Sg-I [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.N?

Worm:Win32/Gamarue.N removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment