Worm

Worm:Win32/Gamarue!pz removal instruction

Malware Removal

The Worm:Win32/Gamarue!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Gamarue!pz?


File Info:

name: B96570D5F0F15091F4E9.mlw
path: /opt/CAPEv2/storage/binaries/743f68f9c3337ae9c52329b28781685b67b1d6010015b74c8d077d7b17a3e8be
crc32: 09BA8DB9
md5: b96570d5f0f15091f4e99a8116cc6e30
sha1: 0fae95608fc6888c5deeb021c362588f7a556c41
sha256: 743f68f9c3337ae9c52329b28781685b67b1d6010015b74c8d077d7b17a3e8be
sha512: 639e79859a038b1d139d1b8c248823fe9c631c9794ed2db9c00831c8fc837b6de7fe7f9bb99b79abe64e41debd2e3916971608f79b2bfa6a26e50eb8c78e36cc
ssdeep: 48:a5zuMqBcq06phM/wwWLSeJY8JTa6Il+Lh1Zytwq4WdGMUk+t/Acm/SegaDiN2xMY:TRphMzf85CwqfdGMUk2/S6eNONWp
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T122A11BDEBFACBDF6C52808394CABD61F395FB4A847DD82829604D23784E2550458897C
sha3_384: 39bd48c7fbf0286d6657e8975e0ecebdc38e1bb37ce6942d8c57d80ff9295b46daf47b2b118a2e3c7d74adee64834040
ep_bytes: 807c2408010f85b901000060be006000
timestamp: 2013-04-10 19:08:06

Version Info:

0: [No Data]

Worm:Win32/Gamarue!pz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Debris.mmkl
Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Razy.777633
FireEyeGeneric.mg.b96570d5f0f15091
CAT-QuickHealTrojan.MauvaiseRI.S5243297
SkyhighBehavesLike.Win32.Dropper.xh
McAfeeGenericRXAA-AA!B96570D5F0F1
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.Bundpil.Win32.146551
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f3241 )
AlibabaWorm:Win32/Debris.6594798e
K7GWTrojan ( 0040f3241 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36802.amPfa8BgVl
VirITWorm.Win32.Generic.FIM
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.V
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SMB
ClamAVWin.Adware.Downware-15
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Razy.777633
NANO-AntivirusTrojan.Win32.Debris.cqrxgi
AvastWin32:Gamarue-BS [Wrm]
TencentTrojan.Win32.Csyr.A
EmsisoftGen:Variant.Razy.777633 (B)
F-SecureTrojan.TR/Downloader.Gen
BaiduWin32.Worm.Agent.d
VIPREGen:Variant.Razy.777633
TrendMicroWORM_GAMARUE.SMB
SophosW32/Gamarue-EG
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminTrojan/Generic.avoof
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Downloader.Gen
VaristW32/Csyr.A!Eldorado
Antiy-AVLTrojan/Win32.Csyr
MicrosoftWorm:Win32/Gamarue!pz
XcitiumWorm.Win32.Bundpil.B@4wfw3i
ArcabitTrojan.Razy.DBDDA1
ViRobotTrojan.Win32.Csyr.3072
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Trojan.PSE.1Y5UO7M
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Razy.777633
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Gamarue!1.9CEB (CLOUD)
YandexTrojan.GenAsa!k9jYT2EoRNc
IkarusTrojan.FileHooker
MaxSecureWorm.Gamarue.aa
FortinetW32/Generic!tr
AVGWin32:Gamarue-BS [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Bundpil.V

How to remove Worm:Win32/Gamarue!pz?

Worm:Win32/Gamarue!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment