Worm

Worm:Win32/Gamarue.U information

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: 4FD3F95AB318E7018A5A.mlw
path: /opt/CAPEv2/storage/binaries/469609d7bc71ca58e23a92b21710c602c8c1c5385408bd2a92f987f689e5f01f
crc32: 66B08CDA
md5: 4fd3f95ab318e7018a5ae02a3bb15b45
sha1: 6217a4626106e9c9988968844f1b13f127bd7bdb
sha256: 469609d7bc71ca58e23a92b21710c602c8c1c5385408bd2a92f987f689e5f01f
sha512: dcdbad536a1e6df37bea744d4a76315b563435a2a4b55e209f45c33d9532d91c3885afb2c95c2715e2df8b57736b82b01a3f4fae97f5c6e6b0f48826be9b5940
ssdeep: 96:DixZjmjtjd8jPjcZGR5TI3c4EJzMim6eK:unSR6bgY4AzMi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T15ED1CD63C1D70AA1E6BD5D372FC1215AB1CA45560B3E7A5021F0A8243DBC4C77F5B36A
sha3_384: 64b2aed155fb06a2dfef58a23382fac12ea24d3f0d77ce09beda2e4849f8475aa310479dd48c2253fd9b53f9d75259a6
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
DrWebTrojan.Starter.7266
MicroWorld-eScanGen:Variant.Barys.431082
ClamAVWin.Adware.Downware-316
FireEyeGeneric.mg.4fd3f95ab318e701
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xt
McAfeeW32/Worm-FKH!4FD3F95AB318
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004436271 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aCYOrNp
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareWorm.Gamarue
AvastWin32:Sg-G [Trj]
TACHYONWorm/W32.Debris.6280.B
EmsisoftGen:Variant.Barys.431082 (B)
F-SecureWorm.WORM/Gamarue.600541
BaiduWin32.Worm.Bundpil.x
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Bundpil
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.992
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment