Worm

Worm:Win32/Ganelp!pz removal guide

Malware Removal

The Worm:Win32/Ganelp!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ganelp!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Worm:Win32/Ganelp!pz?


File Info:

name: 6E19EF86589C760D647F.mlw
path: /opt/CAPEv2/storage/binaries/e77a1fcf6bd56853e98267c113ee5921c1584ce7ae31bad7ef5a8c5a7a80cdd3
crc32: B0D2B907
md5: 6e19ef86589c760d647f3e70f71056c3
sha1: 1cd1b23f710f2465ee8ee1d981d89cec97d951b5
sha256: e77a1fcf6bd56853e98267c113ee5921c1584ce7ae31bad7ef5a8c5a7a80cdd3
sha512: c08d2bd66a9908e4b6243acd7c134ab1cc33119f4e02b656c88fcf4fe7bddcbe32b9598ef0c2d1373efa7bbf016e99b67d406c864566055e29fe2b187e22ecab
ssdeep: 1536:AHtNFk+5wIaVanPSE8GHo7P1A4xVz28nZtonXZIqi1uww:Adk+xagnPm/P1A4xVzfonXDww
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD145B20F301C06AE4E142FDC5A68BB6B6691F307F6850E3D3A276DE56B51F23A3154B
sha3_384: 9f9fe63ff05ec9825e5287d434e45b658dcf7e948fb390a3503df28e0ecd41aeab27c1d9b651320650d2cb95e6d120b2
ep_bytes: 558bec6aff68e077420068a4a9400064
timestamp: 2012-02-11 15:37:28

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Worm:Win32/Ganelp!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.94664
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Autorun.dt
McAfeeW32/Autorun.worm.aacd
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.94664
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 001f4ea51 )
K7GWTrojan ( 001f4ea51 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D171C8
BaiduWin32.Trojan.Agent.dc
VirITTrojan.Win32.Agent3.BHFA
SymantecW32.Griptolo
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.SRG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.BankerSpy-1
KasperskyTrojan-Ransom.Win32.PornoBlocker.ajrm
BitDefenderTrojan.GenericKDZ.94664
NANO-AntivirusTrojan.Win32.PornoBlocker.hjxaqp
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
AvastWin32:Agent-APNJ [Trj]
TencentTrojan.Win32.FakeFolder.uu
EmsisoftTrojan.GenericKDZ.94664 (B)
F-SecureTrojan.TR/Graftor.1103.80
DrWebTrojan.Siggen3.47992
ZillyaTrojan.Agent.Win32.221798
TrendMicroWORM_GANELP.SMIA
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.6e19ef86589c760d
SophosW32/Ganelp-G
SentinelOneStatic AI – Malicious PE
JiangminWorm/Generic.qjz
WebrootW32.Worm.Gen
VaristW32/Agent.KI.gen!Eldorado
AviraTR/Graftor.1103.80
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.Juched
Kingsoftmalware.kb.a.987
XcitiumWorm.Win32.Ganelp.E@7vlcw2
MicrosoftWorm:Win32/Ganelp!pz
ViRobotWorm.Win32.A.Juched.200704.J
ZoneAlarmTrojan-Ransom.Win32.PornoBlocker.ajrm
GDataWin32.Trojan.PSE.106EFJF
GoogleDetected
AhnLab-V3Trojan/Win32.Npkon.R18258
Acronissuspicious
VBA32BScope.Worm.Juched
ALYacTrojan.GenericKDZ.94664
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_GANELP.SMIA
RisingTrojan.Agent!1.C135 (CLASSIC)
IkarusWorm.Win32.Juched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SRG!tr
BitDefenderThetaGen:NN.ZexaF.36608.my1@aSzMGRiG
AVGWin32:Agent-APNJ [Trj]
Cybereasonmalicious.f710f2
DeepInstinctMALICIOUS

How to remove Worm:Win32/Ganelp!pz?

Worm:Win32/Ganelp!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment