Worm

How to remove “Worm:Win32/Ganelp!atmnm”?

Malware Removal

The Worm:Win32/Ganelp!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ganelp!atmnm virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings

How to determine Worm:Win32/Ganelp!atmnm?


File Info:

name: E27D2957BA9FE3490FB7.mlw
path: /opt/CAPEv2/storage/binaries/5ee7ec17e3dcf29a2e8bd20c7bc1a33cf4da72b9bd957dec081b92a6ab9e3d12
crc32: 63C32C72
md5: e27d2957ba9fe3490fb7b4780b4e961d
sha1: 58ff80ac8366be727795c905c7e13fda135087ad
sha256: 5ee7ec17e3dcf29a2e8bd20c7bc1a33cf4da72b9bd957dec081b92a6ab9e3d12
sha512: 81b13ac2b351111976c7f58f65db00c09d3bf9e1509435f51929f21d62becbdb2907c4e2cbc6f26635db5816122b2362cde2c386c05b53cfe544947c03a9a4f0
ssdeep: 3072:5ePgCctxGv4QcU9KQ2BBA2waPx9rzqytmolaQ:VCctxGsWKQ2Bx5x9KiWQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3346C21E301C06AE8E141FDD5EB8B76766C4F301B5890E3C7E13A9E677A5E6B93014B
sha3_384: 7ed3372e854441333b6939b791255a7c18970c32423bd5c8d5ffed3bd159da02f7c596f74a8b67c2df7b63d4643d5cc0
ep_bytes: 558bec6aff68b07742006890a8400064
timestamp: 2009-07-07 00:10:09

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Worm:Win32/Ganelp!atmnm also known as:

BkavW32.FamVT.RenamerY.Trojan
MicroWorld-eScanWorm.Generic.376455
FireEyeGeneric.mg.e27d2957ba9fe349
CAT-QuickHealW32.Virut.G
ALYacWorm.Generic.376455
Cylanceunsafe
ZillyaTrojan.Agent.Win32.167315
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 002a8f0e1 )
AlibabaWorm:Win32/Juched.167e
K7GWTrojan ( 001f4ea51 )
Cybereasonmalicious.7ba9fe
BitDefenderThetaGen:NN.ZexaF.36196.py2@a0dOnqeG
VirITTrojan.Win32.Agent3.AAYG
CyrenW32/Agent.KI.gen!Eldorado
SymantecW32.Griptolo
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.XAG
APEXMalicious
ClamAVWin.Worm.Ganelp-9941285-0
KasperskyHEUR:Worm.Win32.Generic
BitDefenderWorm.Generic.376455
NANO-AntivirusTrojan.Win32.Juched.dfacwp
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.FakeFolder.bba
EmsisoftWorm.Generic.376455 (B)
BaiduWin32.Trojan.Agent.dc
F-SecureTrojan.TR/Spy.Agent.586689
DrWebTrojan.Siggen8.44292
VIPREWorm.Generic.376455
TrendMicroWORM_GANELP.SMIA
McAfee-GW-EditionBehavesLike.Win32.Autorun.dz
Trapminemalicious.high.ml.score
SophosW32/Autorun-BRF
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.117N3WD
JiangminTrojan/Generic.acckw
GoogleDetected
AviraTR/Spy.Agent.586689
Antiy-AVLTrojan/Win32.Inject
XcitiumWorm.Win32.Jushed.KA@4cysvx
ArcabitWorm.Generic.D5BE87
ZoneAlarmHEUR:Worm.Win32.Generic
MicrosoftWorm:Win32/Ganelp!atmnm
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Npkon.R18258
McAfeeW32/Autorun.worm.aacd
MAXmalware (ai score=87)
VBA32Trojan.Occamy
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_GANELP.SMIA
RisingTrojan.Agent!1.C135 (CLASSIC)
YandexTrojan.GenAsa!ceN4aAluftc
IkarusTrojan.Win32.Webprefix
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SRG!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Ganelp!atmnm?

Worm:Win32/Ganelp!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment