Worm

Worm:Win32/Gamarue!rfn information

Malware Removal

The Worm:Win32/Gamarue!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gamarue!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

How to determine Worm:Win32/Gamarue!rfn?


File Info:

crc32: E34C8095
md5: 2e2e5e283c5353f652d3885ae6e2a420
name: 2E2E5E283C5353F652D3885AE6E2A420.mlw
sha1: 07f9bf153ae159f2b0cbacc8465472a02626917d
sha256: 0bb97289b200f15f67cc3e84d72e671a664e3f8261f87e72ca2de6ee2e412432
sha512: e725c0aaa887b78a8bad8e017fe8050b2aeedaf9510876e137fecf48bd9ee251929c5c97c0ccb411758b5234f3b194654435c5fa25f819476725352759dfe4fa
ssdeep: 3072:gQfkF0y2Uo4qxptTpV6zNzYRBxpv5GHqlkJV+g5COEzauptO1hsSOB5:3fkF6UoPT38ilsqUSzaHsSi5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 AVG Netherlands B. V. 2011
FileVersion: 14.0.1000.340
CompanyName: TuneUp Software
LegalTrademarks: TuneUp Utilitiesx2122
ProductName: TuneUp Utilities 2014
ProductVersion: 14.0.1000.340
FileDescription: TuneUp Automatic Program Reactivator
Translation: 0x0000 0x04b0

Worm:Win32/Gamarue!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ser.Razy.8696
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.38400
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005105d81 )
Cybereasonmalicious.83c535
CyrenW32/Cerber.CF.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FTPE
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Razy-7665605-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.8696
NANO-AntivirusTrojan.Win32.Blocker.eqlkpv
MicroWorld-eScanGen:Variant.Ser.Razy.8696
TencentMalware.Win32.Gencirc.10bb5ab9
Ad-AwareGen:Variant.Ser.Razy.8696
SophosML/PE-A + Mal/Cerber-AL
ComodoTrojWare.Win32.Zonidel.FTPE@7579f6
F-SecureHeuristic.HEUR/AGEN.1128849
BitDefenderThetaGen:NN.ZexaF.34670.yq0@au5hFoei
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionRansomware-GBN!2E2E5E283C53
FireEyeGeneric.mg.2e2e5e283c5353f6
EmsisoftGen:Variant.Ser.Razy.8696 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bmkob
AviraHEUR/AGEN.1128849
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftWorm:Win32/Gamarue!rfn
ArcabitTrojan.Ser.Razy.D21F8
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ser.Razy.8696
AhnLab-V3Win-Trojan/Cerber.Gen
McAfeeRansomware-GBN!2E2E5E283C53
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!zJ2zVVAx4GA
IkarusTrojan-Ransom.Cerber
FortinetW32/Injector.EETM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBPGUA

How to remove Worm:Win32/Gamarue!rfn?

Worm:Win32/Gamarue!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment