Click on screenshot to zoom
Danger level 9
Type: Worms
Common infection symptoms:
  • Connects to the internet without permission
  • Installs itself without permissions
  • Slow Computer
  • Slow internet connection

Worm.Gamarue.B

Worm.Gamarue.B is a malware worm infection which spreads through removable media and drives, and also communicates with remote servers to report its infection, and to download additional malware and files to the system. Worm.Gamarue.B was first released on 30 September 2011, and has spread virally across the web. This worm also operates under various aliases, some of which are:

Download Spyware Removal Tool to Remove* Worm.Gamarue.B
  • Quick & tested solution for Worm.Gamarue.B removal.
  • 100% Free Scan for Windows

Trojan/Win32.FakeAV
Trojan.DownLoader5.886
Win32/TrojanDownloader.Agent.QXN
Trojan.Win32.Yakes.glu
Troj/Bredo-KN

Other distribution methods of Worm.Gamarue.B are to use email and spam attachments with a subject reference to a fictitious fake cancelled ACH payment. When the user executes the attachment, the malware copies itself as the following:

%TEMP%\.com

Because of its subtle intrusion into the system, users may find it difficult to identify and remove Worm.Gamarue.B from the system. The presence of the following files and registry modifications will be a clear indication of the presence of Worm.Gamarue.B on the system:

Files:

%TEMP%\.com

The presence of the following registry modifications:

In subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Sets value: "2600"
With data: "%TEMP%\.com"

This worm will download additional malware to the system, and its developers may be able to assume complete control of the infected PC. This makes it extremely dangerous for the user, as all his private info such as usernames and financial info is at risk. The criminal developers may also use the user’s PC as part of Denial of Service (DoS) attacks, and other nefarious activities. Worm.Gamarue.B will connect to the following domains to report its infection to its developers, receive further instructions and to download arbitrary files to the system:

randomcrappy.com
karabasdobryak.eu
loshatemikontara551.ru
serioslyfucked.ru

When all is said and done you will only be able to regain control of your PC if you destroy Worm.Gamarue.B with the help of a powerful security tool. Investing in such a tool will also provide you with adequate protection against future similar attacks.

Download Spyware Removal Tool to Remove* Worm.Gamarue.B
  • Quick & tested solution for Worm.Gamarue.B removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Worm.Gamarue.B

Files associated with Worm.Gamarue.B infection:

msdubmna.scr
dubmnaxxxzeure.com
bidngimwdkfeue.exe
dadd69ff0012914b.exe
msdubmnax.pif
rlxsunsfdcuww.com
aomrlsi.exe
fhgpgivn.com
zbazqoflacqlt.com
uphvivas.com
aij.exe
czhoybstc.scr
9af8c6a4adb2839c.exe
dubmnaxxxzeure.exe
cec045d216989fdd.exe
964c6dff0034d9c9.exe
b96cff6c00934693.exe
acddff6800975322.exe
92daff7900866d25.exe
6fc2fffe.com
de95fea4015b216a.exe
a3dbfecc01335c24.exe
bf8cfc2403db4073.exe
e46dffd0002f1b92.exe
e3b4fff700081c4b.exe
c003fffd00023ffc.exe
bb42ffd5002a44bd.exe
b1e3ff7e.com
9b58fffc000364a7.exe
943effa2005d6bc1.exe
83eefffc00037c11.exe
801bfffd.com
515ffffc0003aea0.exe
4223faf7.com
3d03ff60009fc2fc.exe
3571ffff0000ca8e.exe
12caeae71518ed35.exe
0c0aff1c00e3f3f5.exe
0b65ffff0000f49a.exe
ffc9fe83.com
6b2dcc8d.com
HVVVelIBBtPNA1.exe
DealScoutUpdateCheck.exe
ComboFix.exe
5df6ffed.com

Worm.Gamarue.B processes to kill:

bidngimwdkfeue.exe
dadd69ff0012914b.exe
aomrlsi.exe
aij.exe
9af8c6a4adb2839c.exe
dubmnaxxxzeure.exe
cec045d216989fdd.exe
964c6dff0034d9c9.exe
b96cff6c00934693.exe
acddff6800975322.exe
92daff7900866d25.exe
de95fea4015b216a.exe
a3dbfecc01335c24.exe
bf8cfc2403db4073.exe
e46dffd0002f1b92.exe
e3b4fff700081c4b.exe
c003fffd00023ffc.exe
bb42ffd5002a44bd.exe
9b58fffc000364a7.exe
943effa2005d6bc1.exe
83eefffc00037c11.exe
515ffffc0003aea0.exe
3d03ff60009fc2fc.exe
3571ffff0000ca8e.exe
12caeae71518ed35.exe
0c0aff1c00e3f3f5.exe
0b65ffff0000f49a.exe
HVVVelIBBtPNA1.exe
DealScoutUpdateCheck.exe
ComboFix.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.