Worm

Should I remove “Worm:Win32/Gamarue.N”?

Malware Removal

The Worm:Win32/Gamarue.N is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.N virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.N?


File Info:

name: DE3A9767A48870290BDD.mlw
path: /opt/CAPEv2/storage/binaries/5296cdf137a71f33b942aab3a6b8d3052e72b71fb19057c35e9f264915ff1d22
crc32: D7408662
md5: de3a9767a48870290bdd8b9ec9113c71
sha1: 460149e0cea7cdd0c7ca9cf12af69e510842d439
sha256: 5296cdf137a71f33b942aab3a6b8d3052e72b71fb19057c35e9f264915ff1d22
sha512: 7733900cdf6cd736e4640e386fd5fee4d1014661cb67f71dd363d3ace60bf196bcb858d75fda4e3da68e98d0953c7449e15ec8b34b5803c04465971fbfb5186d
ssdeep: 48:C+Ubwu9hrN5c8/Yc4cA/c4UBPmIg7o2cqmXB:uhrNvQYA/4wIg7jmXB
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18781613B93647A33D0842B3329E750C7BEBD67A013A04A2F84831A05244153BDD6FF86
sha3_384: 0dae3bb186228f72b47815816368de43170a7c2de460e33d32fa504c595b816862ee4341a4651df494af254cb737f281
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-03-15 18:12:29

Version Info:

0: [No Data]

Worm:Win32/Gamarue.N also known as:

BkavW32.FamVT.DebrisB.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.30878484
FireEyeGeneric.mg.de3a9767a4887029
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Downloader.xz
McAfeeDownloader-FKP!DE3A9767A488
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.23
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004d2f401 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BitDefenderThetaGen:NN.ZedlaF.36744.aq4@a4uKeIf
VirITWorm.Win32.Generic.FXY
SymantecBackdoor.Trojan
ESET-NOD32Win32/Bundpil.J
APEXMalicious
ClamAVWin.Worm.Bundpil-3
KasperskyWorm.Win32.Debris.b
BitDefenderTrojan.GenericKD.30878484
NANO-AntivirusTrojan.Win32.Bundpil.jvbysv
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Downloader-TBF [Trj]
EmsisoftTrojan.GenericKD.30878484 (B)
BaiduWin32.Worm.Bundpil.z
F-SecureTrojan.TR/Rogue.kdz.409654
DrWebTrojan.MulDrop4.25343
VIPRETrojan.GenericKD.30878484
TrendMicroWORM_GAMARUE.SMB
Trapminemalicious.moderate.ml.score
SophosTroj/Loader-M
IkarusTrojan.SuspectCRC
MAXmalware (ai score=82)
GDataWin32.Worm.Debris.A
JiangminWorm/Bundpil.b
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Rogue.kdz.409654
VaristW32/Csyr.A!Eldorado
Antiy-AVLWorm/Win32.Bundpil
Kingsoftmalware.kb.a.996
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Generic.D1D72B14
ViRobotWorm.Win32.Bundpil.4096
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.N
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
VBA32BScope.Worm.Debris
ALYacTrojan.GenericKD.30878484
TACHYONWorm/W32.Bundpil.4096
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMARUE.SMB
RisingWorm.Gamarue!1.68D7 (CLASSIC)
YandexTrojan.GenAsa!uEcSV6bgqXU
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Bundpil.abr
FortinetW32/Bundpil.K!tr
AVGWin32:Downloader-TBF [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.N?

Worm:Win32/Gamarue.N removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment