Worm

Worm:Win32/Gamarue!pz removal instruction

Malware Removal

The Worm:Win32/Gamarue!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!pz virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Gamarue!pz?


File Info:

name: 9D71E135B4D2B425142F.mlw
path: /opt/CAPEv2/storage/binaries/e4e86a8a8c7f57335433824ec6a79258006be99bc54370a1df21bb3eb2e8e3de
crc32: 0127F516
md5: 9d71e135b4d2b425142fbd758d7f574d
sha1: 9bfccda20217fed0c7e154b6ae74b072d13b84f1
sha256: e4e86a8a8c7f57335433824ec6a79258006be99bc54370a1df21bb3eb2e8e3de
sha512: 9bec21151ff013e5d724d061a56649d1fa6bbf54a642cd87404b11636a32f6dec1f69230e5cd316fd1b67f0f7e2a1735675f586610009928013f9ce8530fc3f4
ssdeep: 24:e31GSEuVCeeC/xGVu9dRNtmM4rHOjhgtt2Tkoy8kUBElEBmxVyacVHHdoCT:CfeCwu9aVrH8//RBPmezHWCT
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T109815E7B27746A32E014277319E716D779FA2B6413A0010E89521A082450233DC6FB47
sha3_384: 71ceaadaf8b9f86beae6fa0ee562ff3a03eea8435e0716d61fbb8d9a2fb9a2955951aed878a6f1fe96e333b8c73737dd
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-03-21 14:00:30

Version Info:

0: [No Data]

Worm:Win32/Gamarue!pz also known as:

BkavW32.FamVT.DebrisB.Worm
LionicWorm.Win32.Debris.mrOb
MicroWorld-eScanGen:Variant.Mikey.113463
ClamAVWin.Worm.Bundpil-2
FireEyeGeneric.mg.9d71e135b4d2b425
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Downloader.xz
McAfeeDownloader-FJL!9D71E135B4D2
Cylanceunsafe
VIPREGen:Variant.Mikey.113463
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
AlibabaWorm:Win32/Debris.6e7374f8
K7GWTrojan ( 004c69521 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Agent.am
VirITTrojan.Win32.Generic.TNU
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bundpil.K
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Mikey.113463
NANO-AntivirusTrojan.Win32.Bundpil.cqkxpv
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Downloader-TBF [Trj]
TencentTrojan.Win32.Csyr.A
TACHYONWorm/W32.Bundpil.4096.B
EmsisoftGen:Variant.Mikey.113463 (B)
F-SecureWorm.WORM/Bundil.EB.1
DrWebTrojan.MulDrop4.32540
ZillyaWorm.DebrisGen.Win32.17
TrendMicroWORM_GAMARUE.SMB
SophosW32/Gamarue-BM
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Debris.A
JiangminWorm/Bundpil.a
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Bundil.EB.1
Antiy-AVLWorm/Win32.Bundpil
KingsoftWin32.Worm.Debris.b
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Mikey.D1BB37
ZoneAlarmWorm.Win32.Debris.b
MicrosoftWorm:Win32/Gamarue!pz
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36680.aq4@aGdl9Fp
ALYacGen:Variant.Mikey.113463
MAXmalware (ai score=100)
VBA32BScope.Worm.Debris
MalwarebytesBundpil.Worm.AutoRun.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMARUE.SMB
RisingStealer.OnlineGames!1.9C7A (CLASSIC)
YandexTrojan.GenAsa!IeKNxemGFaI
IkarusWorm.Win32.Bundpil
MaxSecureWorm.W32.Bundpil.abr
FortinetW32/Bundpil.K!tr
AVGWin32:Downloader-TBF [Trj]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Gamarue!pz?

Worm:Win32/Gamarue!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment