Worm

Worm:Win32/Gamarue!ml malicious file

Malware Removal

The Worm:Win32/Gamarue!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!ml virus can do?

  • Performs some HTTP requests
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings

Related domains:

api.wipmania.com

How to determine Worm:Win32/Gamarue!ml?


File Info:

crc32: 458020AD
md5: fcbb520e5c66b1f024440e4eea650686
name: 64.exe
sha1: 710a7bd0d4791edc0f75d8d778c173c981120b5d
sha256: f2af7f2de72d42d045309ea26b6c19076a42b4e6703fb15b5d40416ab37a8052
sha512: 0be757dd903f53394cfd46869e3694aa68f95efe1fcfba24649e9fdc33c489a4095fe0a22a5a50da4ae9cba35251790b0943365bf02fb52d7f6de3fa5173a733
ssdeep: 1536:bsH4+Z6e8Dgy3rGkeFXlJkQqoNZVHZUT81HJ1:YH4hnd3rHeF1JkQquZVHD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Gamarue!ml also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.39
FireEyeGeneric.mg.fcbb520e5c66b1f0
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Trojan.f13
McAfeeGenericRXMG-GR!FCBB520E5C66
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Heur.Mint.Zard.39
K7GWTrojan ( 005533551 )
Cybereasonmalicious.e5c66b
TrendMicroTROJ_GEN.R002C0PJN20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Reconyc.gen
AlibabaWorm:Win32/Phorpiex.d6c675f1
AegisLabTrojan.Multi.Generic.4!c
RisingWorm.Phorpiex!1.CA88 (CLASSIC)
Ad-AwareGen:Heur.Mint.Zard.39
SophosMal/Generic-S
ComodoMalware@#22999xjy9jkw0
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.Siggen10.14421
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.OxyPump.lm
EmsisoftGen:Heur.Mint.Zard.39 (B)
SentinelOneDFI – Malicious PE
JiangminTrojan.Generic.gicux
WebrootW32.Trojan.Gen
AviraTR/Downloader.Gen
MAXmalware (ai score=87)
MicrosoftWorm:Win32/Gamarue!ml
ArcabitTrojan.Mint.Zard.39
ZoneAlarmHEUR:Trojan.Win32.Reconyc.gen
GDataGen:Heur.Mint.Zard.39
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vilsel.C4197391
VBA32BScope.Trojan.Reconyc
ALYacGen:Heur.Mint.Zard.39
MalwarebytesTrojan.Phorpiex
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Phorpiex.V
TrendMicro-HouseCallTROJ_GEN.R002C0PJN20
TencentWin32.Trojan.Reconyc.Egyd
IkarusWorm.Win32.Phorpiex
eGambitUnsafe.AI_Score_100%
FortinetW32/Generic.V!tr
BitDefenderThetaAI:Packer.B6CA0C8D1F
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Gamarue!ml?

Worm:Win32/Gamarue!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment