Worm

What is “Worm:Win32/Gamarue.U”?

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: 4BF448B7797D7A66A3E4.mlw
path: /opt/CAPEv2/storage/binaries/8f320eff23dd0cb8761936411b2dacb0de30aa058f6799a9d35c9e7f998c5e0b
crc32: 2F0D9446
md5: 4bf448b7797d7a66a3e47b9ac92ef488
sha1: 14d727a917d38a9b4ba859e09e1f4bb0bbd34311
sha256: 8f320eff23dd0cb8761936411b2dacb0de30aa058f6799a9d35c9e7f998c5e0b
sha512: 3fe37738f9d67bb7ee46dae3c5ccfa08cae55a60bc5d5217ee36c0bf8369ed3f3fbadace08c853e5d60a25a132c5ad6930191b91258e0a352e18e7e3942d1930
ssdeep: 96:DixZjmjtjd8jPjcZGR5TImF+L34CqHtWMq6r8Uw7XRJRwUq8xC:unSR6bgYG37qHtWM1r8Uw7X9wUq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T169D14415D1B248E3DFE56AB71C8C902B78DC0613EEB4325CA28499CC20C499F7ECE5B6
sha3_384: 36b0455ea5793bac7bc10cec8ba2d4f2872ca2be3a86a5818b8e6d04ff17d397f929b4e06bf3a08aaa2c986562e55a9c
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
DrWebTrojan.Starter.7266
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.4bf448b7797d7a66
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xt
McAfeeW32/Worm-FKH!4BF448B7797D
Cylanceunsafe
VIPREGen:Variant.Barys.431082
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004436271 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aCYOrNp
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareWorm.Gamarue
AvastWin32:Sg-G [Trj]
TencentWorm.Win32.Debris.a
SophosTroj/Agent-ACCV
F-SecureWorm.WORM/Gamarue.600541
BaiduWin32.Worm.Bundpil.x
ZillyaWorm.DebrisGen.Win32.28
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.431082 (B)
IkarusWorm.Win32.Bundpil
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.989
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
YandexTrojan.GenAsa!epZR9n5ihTQ
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.j
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment