Home / malwarePDF  


First posted on 01 March 2013.
Source: Microsoft

Aliases :

There are no other names known for Worm:Win32/Gamarue.O.

Explanation :

Worm:Win32/Gamarue.O contains code that is loaded and executed by Worm:Win32/Gamarue.N.

It may have the file name "desktop.ini".

When run, the malware connects to a remote host at the following location:


From there, it downloads a file which is saved as "thumbs.db". The file is then decrypted and saved as the following:


Worm:Win32/Gamarue.O then runs this file.

For more information about the Worm:Win32/Gamarue family, see the description elsewhere in the encyclopedia.

Analysis by Ray Roberts

Last update 01 March 2013