Worm

Worm:Win32/Gamarue!pz malicious file

Malware Removal

The Worm:Win32/Gamarue!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!pz virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue!pz?


File Info:

name: F18AFB6B11DD6C833A0F.mlw
path: /opt/CAPEv2/storage/binaries/7ee10362adf430025e6f54b2ad24d2b79f9ec409e58b198fdc9d6c764fe00b31
crc32: 3505663E
md5: f18afb6b11dd6c833a0fe35b02e35a53
sha1: 9f3c3c2776b855ab00197c4f79cec0bd6c47f79a
sha256: 7ee10362adf430025e6f54b2ad24d2b79f9ec409e58b198fdc9d6c764fe00b31
sha512: eedf44d2c13efb42c68e5a53ed9673d7f9f96a0383a95a6dd79ba9e3f96c3cd674b30f10ef4ac38076822f3844d04f6339c79813e990349b517e818f3868c469
ssdeep: 24:e1GS41F3CeG6/dGVa9dRNtz/4re/a/MProXEBGZUV1H6W5wI1Wj:SWG6l6a9/ArrDUBGZ6pewWj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C871633747A45A73F1AC6737399B20D779B95A6427A0870E8BD126190442237AF79A03
sha3_384: 68a5bb389ee02e5d79b4a478308436336d40199ab7a0b7a4636715342681d9ceaad9b4aa07e5a2773e3d2fdf0cdef954
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-03-29 16:19:20

Version Info:

0: [No Data]

Worm:Win32/Gamarue!pz also known as:

BkavW32.FamVT.DebrisB.Worm
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Zusy.320735
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zz
McAfeeDownloader-FJN!F18AFB6B11DD
MalwarebytesTrojan.Bundpil
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWEmailWorm ( 0040f50c1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D4E4DF
BitDefenderThetaGen:NN.ZedlaF.36744.aq4@a06SOkd
VirITTrojan.Win32.Generic.AMUP
SymantecTrojan Horse
ESET-NOD32Win32/Bundpil.O
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Bundpil-1
KasperskyWorm.Win32.Bundpil.abt
BitDefenderGen:Variant.Zusy.320735
NANO-AntivirusTrojan.Win32.Bundpil.cqkybb
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-TBF [Trj]
TencentTrojan.Win32.Csyr.A
EmsisoftGen:Variant.Zusy.320735 (B)
F-SecureTrojan.TR/Rogue.kdj.14
BaiduWin32.Worm.Bundpil.w
VIPREGen:Variant.Zusy.320735
TrendMicroWORM_GAMARUE.SMB
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f18afb6b11dd6c83
SophosTroj/Agent-ABAG
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Zapchast.igo
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraTR/Rogue.kdj.14
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.Bundpil
Kingsoftmalware.kb.a.758
XcitiumWorm.Win32.Bundpil.T@4wizl6
MicrosoftWorm:Win32/Gamarue!pz
ZoneAlarmWorm.Win32.Bundpil.abt
GDataGen:Variant.Zusy.320735
GoogleDetected
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
VBA32Trojan.Csyr
ALYacGen:Variant.Zusy.320735
TACHYONTrojan/W32.Small.3584.GX
Cylanceunsafe
PandaTrj/Agent.JIQ
TrendMicro-HouseCallWORM_GAMARUE.SMB
RisingWorm.Win32.Gamarue.s (CLASSIC)
YandexTrojan.GenAsa!lbCnv+3Wzlg
IkarusTrojan.Win32.Zapchast
MaxSecureWorm.W32.Bundpil.abt
FortinetW32/Generic.AC.4644C9
AVGWin32:Downloader-TBF [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue!pz?

Worm:Win32/Gamarue!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment