Worm

Worm:Win32/Gamarue.U information

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: CE73868BD3CD5C1B5F13.mlw
path: /opt/CAPEv2/storage/binaries/0f8348c2abff493b6ef5ed9f15d0416e0eb64d57871786949f2b491c882db3b2
crc32: 6D3AC3EB
md5: ce73868bd3cd5c1b5f13969862fba545
sha1: 1acd5d4fd546e9671411508fef355e531b4e9db4
sha256: 0f8348c2abff493b6ef5ed9f15d0416e0eb64d57871786949f2b491c882db3b2
sha512: 7dd124fc50380487c30389a67c18460a1423c993234c5a20c1aa96b8e4eb566441dc9296e54a0c9686d9471690bc5b321c2e8904a627f3545ce80db8df173420
ssdeep: 96:DixZjmjtjd8jPjcZGR5TIr6I+iox8+jPCS5YE5n885k3:unSR6bgYXXxPl5YE5885
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FBC1B30BC3B05963DE8C1B771E9E34CB64EC1C125DB06920A1F5AE4823D044FACCE66E
sha3_384: adf522350723060ad6b6fc70210a106e4d993ce6b393ee08d61dbe6926859f274d0d9d3d65b1e80878bf36ea8c9b8e03
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.ce73868bd3cd5c1b
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FKH!CE73868BD3CD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004436271 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BaiduWin32.Worm.Bundpil.x
SymantecTrojan Horse
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareWorm.Gamarue
AvastWin32:Sg-G [Trj]
TencentWorm.Win32.Debris.a
TACHYONWorm/W32.Debris.6070.B
SophosTroj/Agent-ACCV
F-SecureWorm.WORM/Gamarue.600541
DrWebTrojan.Starter.7266
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.431082 (B)
IkarusWorm.Win32.Bundpil
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.984
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aCYOrNp
MAXmalware (ai score=85)
VBA32Worm.Gamarue
Cylanceunsafe
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
YandexTrojan.GenAsa!epZR9n5ihTQ
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment