Worm

Worm:Win32/Gamarue.U removal instruction

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: DE791FFF3AB944A3D277.mlw
path: /opt/CAPEv2/storage/binaries/9d8806183f3e3dc4c1f49ab3d87e95e3b6f3f56eec975d15a92d0fa9ac942c97
crc32: 8F971F19
md5: de791fff3ab944a3d2775e85b46e791d
sha1: 00e9a49a82c422677021d45ce94d056037cf8eee
sha256: 9d8806183f3e3dc4c1f49ab3d87e95e3b6f3f56eec975d15a92d0fa9ac942c97
sha512: 4525477bf3bbf8c2809b5c4ec5eddc7bc54afa3dfbf09fe0ea35ead67d25faa102c26d829be3fc73d46668a798122a42a8259e7c67b7b876c8ae2118f7165613
ssdeep: 96:DixZjmjtjd8jPjcZGR5TIXpsILMt/0d6n0FNMGdqCZOLPZVj0xfHt7:unSR6bgYWNLM90dBFNlbZOLP/j0xfHt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1BDF1FF268393C4D2D74C4AFECD18648E78D77906BDE11B607388096819C46CF7BEB7A9
sha3_384: d69b6f24f6a44c02504f5385caf9da7bf06ebc2f6ef64ca45bf3a25109596afa27eb7d793353fce918355c22c2ed8bb6
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-02 20:43:59

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
DrWebTrojan.Starter.7266
MicroWorld-eScanGen:Variant.Barys.431082
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FKH!DE791FFF3AB9
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.DebrisGen.Win32.28
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aCYOrNp
VirITWorm.Win32.Generic.GJU
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AI
APEXMalicious
ClamAVWin.Adware.Downware-316
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssodu
SUPERAntiSpywareBackdoor.Bot/Variant
AvastWin32:Sg-G [Trj]
TencentWorm.Win32.Debris.a
EmsisoftGen:Variant.Barys.431082 (B)
F-SecureWorm.WORM/Gamarue.600541
BaiduWin32.Worm.Bundpil.x
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
FireEyeGeneric.mg.de791fff3ab944a3
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Bundpil
MAXmalware (ai score=84)
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Debris.b
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.600541
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ViRobotTrojan.Win32.Agent.6329
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68931
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.431082
TACHYONWorm/W32.Debris.7631.B
Cylanceunsafe
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment