Home Malware Programs Worms Worm.Gamarue.F

Worm.Gamarue.F

Posted: February 13, 2012

Threat Metric

Ranking: 16,754
Threat Level: 5/10
Infected PCs: 4,850
First Seen: February 13, 2012
Last Seen: October 11, 2023
OS(es) Affected: Windows

Aliases

Dropper.Generic5.BTZT [AVG]W32/Jorik_Morkov.A!tr [Fortinet]Trojan.Win32.Vilsel [Ikarus]Heuristic.BehavesLike.Win32.Downloader.H [McAfee-GW-Edition]Gen:Variant.Barys.686 [BitDefender]Trojan.Win32.Jorik.Morkov.a [Kaspersky]Win32:VBCrypt-AIF [Trj] [Avast]a variant of Win32/Injector.PMR [NOD32]Trj/Bublik.A [Panda]Downloader.Generic13.AACI [AVG]W32/Injector.ZNR!tr [Fortinet]Worm/Win32.Stekct [AhnLab-V3]TR/Spy.ZBot.EB.174 [AntiVir]Trojan.Winlock.7858 [DrWeb]Rogue:W32/FakeAv.LC [F-Secure]
More aliases (1288)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Local Settings\Temp\ccbovyi.com File name: ccbovyi.com
Size: 97.28 KB (97280 bytes)
MD5: 091999351f12b922b46b9f123852a6a8
Detection count: 890
File type: Command, executable file
Mime Type: unknown/com
Path: C:\Users\<username>\Local Settings\Temp\ccbovyi.com
Group: Malware file
Last Updated: October 11, 2023
%SYSTEMDRIVE%\System Volume Information\SystemRestore\FRStaging\Users\<username>\AppData\Local\Temp\ccwpxw.exe File name: ccwpxw.exe
Size: 82.94 KB (82944 bytes)
MD5: 7ed265b1caa48a7eeb2246bb365778d8
Detection count: 698
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\System Volume Information\SystemRestore\FRStaging\Users\<username>\AppData\Local\Temp\ccwpxw.exe
Group: Malware file
Last Updated: July 5, 2023
C:\ProgramData\Local Settings\Temp\ccaibbcx.com File name: ccaibbcx.com
Size: 283.64 KB (283648 bytes)
MD5: d47f069cd335095c3c2e1ee3d165dd33
Detection count: 365
File type: Command, executable file
Mime Type: unknown/com
Path: C:\ProgramData\Local Settings\Temp\ccaibbcx.com
Group: Malware file
Last Updated: July 3, 2023
%ALLUSERSPROFILE%\Local Settings\Temp\msvaawxbo.exe File name: msvaawxbo.exe
Size: 44.39 KB (44391 bytes)
MD5: 3eb6270f1e883af3a86815aa6ec949f2
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: April 29, 2013
%USERPROFILE%\Local Settings\Temp\msajoyhia.exe File name: msajoyhia.exe
Size: 47.92 KB (47920 bytes)
MD5: d44350d7f5ed55e2da03e2d7f1e7d41e
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 21, 2013
%USERPROFILE%\Local Settings\Temp\msybzi.exe File name: msybzi.exe
Size: 64.37 KB (64376 bytes)
MD5: 5b5fe33426175cd59f9814ad1df55844
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 8, 2013
C:\Users\<username>\Local Settings\Temp\mstzywvnf.pif File name: mstzywvnf.pif
Size: 54.34 KB (54344 bytes)
MD5: 24924ed88a342f6ecdd109f4046d099f
Detection count: 82
Mime Type: unknown/pif
Path: C:\Users\<username>\Local Settings\Temp\mstzywvnf.pif
Group: Malware file
Last Updated: January 9, 2022
%USERPROFILE%\Local Settings\Temp\mseapuc.bat File name: mseapuc.bat
Size: 65.02 KB (65024 bytes)
MD5: 4915d5f3d1718e326944cb0563716191
Detection count: 76
File type: Batch file
Mime Type: unknown/bat
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: March 4, 2013
%USERPROFILE%\Local Settings\Temp\msyoria.scr File name: msyoria.scr
Size: 62.97 KB (62976 bytes)
MD5: 354692cc12def33967175296ad6584ac
Detection count: 56
Mime Type: unknown/scr
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: February 6, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msagdf.cmd File name: msagdf.cmd
Size: 70.14 KB (70144 bytes)
MD5: 98b1ed15f6777190c7d258c5777418d3
Detection count: 53
Mime Type: unknown/cmd
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: May 8, 2013
%USERPROFILE%\Local Settings\Temp\msehvi.exe File name: msehvi.exe
Size: 50.5 KB (50504 bytes)
MD5: d1a61f7fd72bd8933692c9efbcb17c29
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: February 25, 2013
%USERPROFILE%\Local Settings\Temp\msnwea.bat File name: msnwea.bat
Size: 64.37 KB (64376 bytes)
MD5: 1cdfae6645aa9423e12f34b61fd9fb9e
Detection count: 35
File type: Batch file
Mime Type: unknown/bat
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 5, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msigpoeic.pif File name: msigpoeic.pif
Size: 50.41 KB (50416 bytes)
MD5: 43da553c10b4153cf6c71f1e5d1fc82f
Detection count: 32
Mime Type: unknown/pif
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 29, 2013
%USERPROFILE%\Local Settings\Temp\msookjsaq.exe File name: msookjsaq.exe
Size: 35.2 KB (35200 bytes)
MD5: d360dff62fca3acee479a1fbce4bfdf1
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: December 11, 2012
%USERPROFILE%\Local Settings\Temp\msorqze.bat File name: msorqze.bat
Size: 70.14 KB (70144 bytes)
MD5: f3bd9f6300ab86b917a308bec5ef9fc3
Detection count: 9
File type: Batch file
Mime Type: unknown/bat
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: October 17, 2018
%ALLUSERSPROFILE%\Local Settings\Temp\mszxxqi.com File name: mszxxqi.com
Size: 39.42 KB (39424 bytes)
MD5: dc38c884284813b1bb90c43901c53469
Detection count: 7
File type: Command, executable file
Mime Type: unknown/com
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: December 28, 2012
%ALLUSERSPROFILE%\Local Settings\Temp\msfuoa.cmd File name: msfuoa.cmd
Size: 111.1 KB (111104 bytes)
MD5: 96de1a206d03939f07dbaccea2cb55a4
Detection count: 5
Mime Type: unknown/cmd
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: November 12, 2012
%ALLUSERSPROFILE%\Local Settings\Temp\msuyyzukr.exe File name: msuyyzukr.exe
Size: 1.38 MB (1385984 bytes)
MD5: 6734646d5d9abb7d11f8055e1b41b9f9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: November 12, 2012
%APPDATA%\xzwonskxd3jma2i1ecthvydloaprl2wo2\svcnost.exe File name: svcnost.exe
Size: 425.47 KB (425472 bytes)
MD5: a5b761ea2ed32039abb6bb642b305062
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\xzwonskxd3jma2i1ecthvydloaprl2wo2
Group: Malware file
Last Updated: February 25, 2013
%USERPROFILE%\Local Settings\Temp\msvaocaoi.exe File name: msvaocaoi.exe
Size: 43 KB (43000 bytes)
MD5: 4b78fa2de54c60d5f56f485685fba6e3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: February 14, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msqaczae.com File name: msqaczae.com
Size: 83.96 KB (83968 bytes)
MD5: d77897ceed547a8a4fe98b79270a24aa
Detection count: 4
File type: Command, executable file
Mime Type: unknown/com
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: April 8, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msxxwgayr.exe File name: msxxwgayr.exe
Size: 45.05 KB (45056 bytes)
MD5: 5c2c38b0fb9530a2db98cee9b5808592
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 8, 2013

More files
Loading...