Worm

Worm:Win32/Gamarue!B malicious file

Malware Removal

The Worm:Win32/Gamarue!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Gamarue!B?


File Info:

name: E64F39BC6E781DDCC7AF.mlw
path: /opt/CAPEv2/storage/binaries/83c9b18ab47a9aa7e1073ee070818ebfd4b7792de8a88f0faefed2eec815e0bf
crc32: 52622E6A
md5: e64f39bc6e781ddcc7afe4cdbea5a0d0
sha1: e4bfd24e15b7c903bd8b2c183686b08eddcf6d6c
sha256: 83c9b18ab47a9aa7e1073ee070818ebfd4b7792de8a88f0faefed2eec815e0bf
sha512: 92a2ee3a6807a440a2dc1ca7d67a3493243b113f12ef7bfe95510885a4627eba67bf7aa421a8eb7d73d83f20b7023898832770277ce11ed2e53fb1c3ac799f56
ssdeep: 1536:IV4PykfMqFFAWE3pN6UWH7ICH55xTXSOBWcAfJ:4kI+SJZdQj5xT7AfJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B853CF55265538C7C2A73930C655EB8A9F7DFFE2B46C842A0848D32D4E02748D6C9AFB
sha3_384: 9c5f12536a6ad18f4a16efe9e7c3d6237557cd13163fd0b667215ad8590121c7846eab7ad1ca77757e24b2dc8412359d
ep_bytes: 558bec81ec18010000682c01000068a4
timestamp: 2014-02-07 23:51:44

Version Info:

CompanyName: Mission Complete
FileDescription: Mission LTD.
FileVersion: 1.23.0.1
InternalName: Mission
LegalCopyright: Copyright (C) 2014
OriginalFilename: Mission
ProductName: Mission Pack Name
ProductVersion: 1.0.12.1
Translation: 0x0409 0x04b0

Worm:Win32/Gamarue!B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.9017
FireEyeGeneric.mg.e64f39bc6e781ddc
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.624102
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004950fd1 )
AlibabaTrojan:Win32/Kryptik.edf162ed
K7GWTrojan ( 004950fd1 )
Cybereasonmalicious.e15b7c
BitDefenderThetaGen:NN.ZexaF.36350.eG0@aC47hQei
VirITTrojan.Win32.Generic.AAVF
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BUPU
ZonerTrojan.Win32.32255
APEXMalicious
AvastWin32:Kryptik-NKI [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Blocker.cxpbhy
TencentWin32.Trojan.Generic.Hajl
SophosTroj/Agent-AFZM
F-SecureTrojan.TR/Patched.Ren.Gen3
McAfee-GW-EditionPWSZbot-FRG!E64F39BC6E78
Trapminemalicious.high.ml.score
JiangminTrojan.Generic.ayava
WebrootTrojan.Dropper.Gen
AviraTR/Patched.Ren.Gen3
Antiy-AVLTrojan[Ransom]/Win32.Blocker
XcitiumMalware@#qaxe23g93k1v
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Gamarue.gen!B
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R97406
Acronissuspicious
VBA32BScope.Trojan.Winlock
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1001
PandaGeneric Malware
RisingStealer.Zbot!8.109D7 (TFE:2:S4ZynQWbPiO)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.CDCX!tr
AVGWin32:Kryptik-NKI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Gamarue!B?

Worm:Win32/Gamarue!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment