Worm

How to remove “Worm:Win32/Gamarue.U”?

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: ECA20B25ADA6B6107828.mlw
path: /opt/CAPEv2/storage/binaries/21f635f6497920d6f8752d4e164d9881bbe9c001b811553a61c27dbacb0c9dad
crc32: FA71CCDC
md5: eca20b25ada6b6107828dfee5d680c43
sha1: 10e7659f173c35088cc1d2b4f17d72ce69dbc198
sha256: 21f635f6497920d6f8752d4e164d9881bbe9c001b811553a61c27dbacb0c9dad
sha512: 3fb280876ccef35578aff31333388855f622f3779d8e612eac14c1d2c832d92d846bdc43d3ddfa13442a99a3cdaa52274f9da382891303be52fae49ae49f930c
ssdeep: 96:DixZjmjtjd8jPjcZGR5TIW8d4Bav+GGwWYY:unSR6bgYPPBa2GGdP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1ECD18EC28F510F52ED842675E5AB7CA335F435294DB05C88C0A46E249BD5C4A2FEFD2E
sha3_384: 49e64adaad05d6ffdae973be95d5714f9219b6c24af9c71023adfe9a63a7fe8e530210c6030b5d31ff3058b3e301fadb
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
tehtrisGeneric.Malware
DrWebTrojan.Starter.7266
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.eca20b25ada6b610
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xt
McAfeeW32/Worm-FKH!ECA20B25ADA6
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aCYOrNp
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareWorm.Gamarue
AvastWin32:Sg-G [Trj]
TencentWorm.Win32.Debris.a
EmsisoftGen:Variant.Barys.431082 (B)
GoogleDetected
F-SecureWorm.WORM/Gamarue.600541
BaiduWin32.Worm.Bundpil.x
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
SophosTroj/Agent-ACCV
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraWORM/Gamarue.600541
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.985
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
ALYacGen:Variant.Barys.431082
TACHYONWorm/W32.Debris.6280.B
VBA32Worm.Gamarue
Cylanceunsafe
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
YandexTrojan.GenAsa!epZR9n5ihTQ
IkarusWorm.Win32.Bundpil
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment