Worm

Worm:Win32/Gamarue.U malicious file

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: CCB158125505B91C43C8.mlw
path: /opt/CAPEv2/storage/binaries/18e132d133db7daa0da5597367f6c0887dbe1da44138fdf9d8eeaaf2bd2e5768
crc32: 3A3DD2B3
md5: ccb158125505b91c43c80665673eb4e9
sha1: b72642265889c5b1389400cedaba8388d586de16
sha256: 18e132d133db7daa0da5597367f6c0887dbe1da44138fdf9d8eeaaf2bd2e5768
sha512: 584cc67fddf641cd3c27e1c37730ef5c403d07650ffaf0de23869aae4ee8d102f28e1b0a1b6052a0a864387fbd578b391e33e6dd0c86fe942fb9b74852c6ca09
ssdeep: 96:DixZjmjtjd8jPjcZGR5TIhZjVULtWPEBn74MhCeLadDdxYAxEq:unSR6bgY4UF174MhCFxn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T114E1421BC5B3E561EE6AD57F050A44833AED1CE275B0357C20E9670492804CFAED9EBB
sha3_384: bf53f62abb5e153da006b0f05f08d6a969cb6d1da63178f1f96e8d7895ef464107fa94b09a6b74338922854ca64a5fd0
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.ccb158125505b91c
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FKH!CCB158125505
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aCYOrNp
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SML
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareWorm.Gamarue
AvastWin32:Sg-G [Trj]
TencentWorm.Win32.Debris.a
SophosTroj/Agent-ACCV
BaiduWin32.Worm.Bundpil.x
F-SecureWorm.WORM/Gamarue.600541
DrWebTrojan.Starter.7266
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.431082 (B)
IkarusWorm.Win32.Bundpil
MAXmalware (ai score=88)
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.987
MicrosoftWorm:Win32/Gamarue.U
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Worm.Gamarue.AQ
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
TACHYONWorm/W32.Debris.7225.B
Cylanceunsafe
PandaTrj/Vilsel.AF
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
YandexTrojan.GenAsa!epZR9n5ihTQ
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.4783f685

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment