Worm

About “Worm:Win32/Gamarue.U” infection

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: 0E772917F509BFEC2ED4.mlw
path: /opt/CAPEv2/storage/binaries/d5e890bc2a5887c994399342ff52303c29fe512828b0c76e7a479e6603f4fc31
crc32: EB120E64
md5: 0e772917f509bfec2ed4e5c30b0edfae
sha1: 187b25d7fe68da1ca766ee6db28eeb3c45c7f627
sha256: d5e890bc2a5887c994399342ff52303c29fe512828b0c76e7a479e6603f4fc31
sha512: 8d49c0e030ba579873f7f02b34ae55b1fee57c9642180afffc0ba03805b86a4c13a140078d866bcbc64bf32102c226546726d0f19280b90fab2dd7f1a39ff2fc
ssdeep: 96:DixZjmjtjd8jPjcZGR5TIdI93hfCkyk+ckwCfY00TsIB1CSjQqIknId6/PFodhOy:unSR6bgYoIXfyhCU0X/8xyYa2b
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T167F11F9FCB75C911CC5A0ABF0A6D34992099D9274C71FE7240F35BA02990D8E5DCA39D
sha3_384: 1bf6e2a1ecf1deb25487f5db04a1d1aee10f40584bcf203ce5bc5255647bf155bd1f92bf08e0545d3639586a497cf7b8
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.431082
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FKH!0E772917F509
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Bundpil.x
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SML
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareBackdoor.Bot/Variant
AvastWin32:Sg-G [Trj]
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
TACHYONWorm/W32.Debris.7554.E
EmsisoftGen:Variant.Barys.431082 (B)
F-SecureWorm.WORM/Gamarue.600541
DrWebTrojan.Starter.7266
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
FireEyeGeneric.mg.0e772917f509bfec
SophosTroj/Agent-ACCV
SentinelOneStatic AI – Malicious PE
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.981
MicrosoftWorm:Win32/Gamarue.U
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Worm.Gamarue.AQ
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Vilsel.AF
TencentWorm.Win32.Debris.a
YandexTrojan.GenAsa!epZR9n5ihTQ
IkarusWorm.Win32.Bundpil
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aCYOrNp
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.4783f685

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment