Worm

What is “Worm:Win32/Gamarue.U”?

Malware Removal

The Worm:Win32/Gamarue.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue.U virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue.U?


File Info:

name: 3E15E1CD7917DD15D3D2.mlw
path: /opt/CAPEv2/storage/binaries/d86ce55425b9c16ce9cd939dace896a203b9c3d938768ead9450a71c8760b627
crc32: 73549CB3
md5: 3e15e1cd7917dd15d3d2e4ee22fa5645
sha1: 7ea5e5f3bc7da330a4b62dcc9a02e2b79ebc4f2f
sha256: d86ce55425b9c16ce9cd939dace896a203b9c3d938768ead9450a71c8760b627
sha512: cb5b4750710e2e29a30f15a509e47a1ebba8ea707be493a086908c4383dcda3bda69716677542c0a65c2f0f592a33829bbc35e408c7ac8d933b6343d5689f9c8
ssdeep: 96:WLRxkjujtjd8jPjcZG2Uog7rRPPb16ZwnmB5r8qU/RHTFY2i78Lrp++:WtqKR6bgYIUrdp66mBWqU/RHW2G8g+
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T198F11247EA730962DE59183F4D8B1E4218E86C7FA4713D90E0E45E4462A841BFDEBC5E
sha3_384: a0018c516e6ae5b501d475ad1d9fdf54a54df1c11b3f2bf2b82606f80b7fdc09ab2907df6619f013ade01c8f4b23c9bd
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-04 10:32:55

Version Info:

0: [No Data]

Worm:Win32/Gamarue.U also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431082
ClamAVWin.Trojan.Agent-1109032
FireEyeGeneric.mg.3e15e1cd7917dd15
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FKH!3E15E1CD7917
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.26
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWTrojan ( 004436271 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@a8XQObp
VirITWorm.Win32.Generic.GGK
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Bundpil.AI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Agent.bxoygi
AvastWin32:Sg-G [Trj]
EmsisoftGen:Variant.Barys.431082 (B)
BaiduWin32.Worm.Bundpil.a
F-SecureWorm.WORM/Gamarue.600541
DrWebTrojan.MulDrop4.25343
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SML
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Bundpil
GDataWin32.Worm.Gamarue.AQ
JiangminWorm/Agent.coi
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraWORM/Gamarue.600541
Antiy-AVLWorm/Win32.Agent
Kingsoftmalware.kb.a.983
XcitiumTrojWare.Win32.Debris.JOUE@4ygmsm
ArcabitTrojan.Barys.D693EA
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue.U
GoogleDetected
AhnLab-V3Worm/Win32.Agent.R71167
Acronissuspicious
ALYacGen:Variant.Barys.431082
MAXmalware (ai score=84)
VBA32Worm.Gamarue
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMARUE.SML
RisingWorm.Gamarue!1.9CC1 (CLASSIC)
YandexTrojan.GenAsa!W3ioSyJQvNY
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Agent.pvg
FortinetW32/Agent.AF!worm
AVGWin32:Sg-G [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue.U?

Worm:Win32/Gamarue.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment