Worm

Worm:Win32/Gamarue!pz removal instruction

Malware Removal

The Worm:Win32/Gamarue!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!pz virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue!pz?


File Info:

name: 34EA7817A5470D98F804.mlw
path: /opt/CAPEv2/storage/binaries/f57ac79ee44bb434024f41f18412d6c91fbe637aafee161bb11fcf6a8931ac05
crc32: 28FA820B
md5: 34ea7817a5470d98f80410be29e947a7
sha1: e6b7f2d27a6ac8df1620e9ac82789a87c8ce9e50
sha256: f57ac79ee44bb434024f41f18412d6c91fbe637aafee161bb11fcf6a8931ac05
sha512: 60b9c60d9f6a4d0fef85ee1eb761cd051dd9fe5dcf252bdc05f8447e01cf8a076f592448f13c26ee1f79de209b47a988b228bbcd8f4af91959511a2ae3d3680b
ssdeep: 24:e1GS41F3CeG6/dGVa9dRNtz/4re/a/MProXEBGZUV1H6W5wh:SWG6l6a9/ArrDUBGZ6peh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1447163374BA4AA73E16C2737399B20DB79F95A5427A0461E8BC126290442237AF79A03
sha3_384: ec75d8f47f340b1ce7d36716c8ba5829ee71817eaf1a148bd01e624b6a99b20d679a184e0cde606b5a5f8a4b44175377
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-03-29 16:19:20

Version Info:

0: [No Data]

Worm:Win32/Gamarue!pz also known as:

BkavW32.FamVT.DebrisB.Worm
MicroWorld-eScanGen:Variant.Zusy.320735
ClamAVWin.Worm.Bundpil-1
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zz
McAfeeDownloader-FJN!34EA7817A547
MalwarebytesTrojan.Bundpil
VIPREGen:Variant.Zusy.320735
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0040f50c1 )
K7AntiVirusEmailWorm ( 0040f50c1 )
BaiduWin32.Worm.Bundpil.w
VirITTrojan.Win32.Generic.AMUP
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.O
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Bundpil.abt
BitDefenderGen:Variant.Zusy.320735
NANO-AntivirusTrojan.Win32.Bundpil.cqkybb
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-TBF [Trj]
TencentTrojan.Win32.Csyr.A
TACHYONTrojan/W32.Small.3584.GX
EmsisoftGen:Variant.Zusy.320735 (B)
F-SecureTrojan.TR/Rogue.kdj.14
DrWebTrojan.MulDrop4.25343
TrendMicroWORM_GAMARUE.SMB
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.34ea7817a5470d98
SophosTroj/Agent-ABAG
IkarusTrojan.Win32.Zapchast
GDataGen:Variant.Zusy.320735
JiangminTrojan/Zapchast.igo
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Rogue.kdj.14
Antiy-AVLWorm/Win32.Bundpil
Kingsoftmalware.kb.a.865
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Zusy.D4E4DF
ZoneAlarmWorm.Win32.Bundpil.abt
MicrosoftWorm:Win32/Gamarue!pz
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36744.aq4@a06SOkd
ALYacGen:Variant.Zusy.320735
MAXmalware (ai score=87)
VBA32Trojan.Csyr
Cylanceunsafe
PandaTrj/Agent.JIQ
TrendMicro-HouseCallWORM_GAMARUE.SMB
RisingWorm.Win32.Gamarue.s (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.Bundpil.abt
FortinetW32/Generic.AC.4644C9
AVGWin32:Downloader-TBF [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue!pz?

Worm:Win32/Gamarue!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment