Threat Database Trojans TrojanDropper:Win32/Gamarue.A

TrojanDropper:Win32/Gamarue.A

By ZulaZuza in Trojans

Threat Scorecard

Ranking: 16,596
Threat Level: 90 % (High)
Infected Computers: 42
First Seen: August 14, 2013
Last Seen: July 11, 2023
OS(es) Affected: Windows

TrojanDropper:Win32/Gamarue.A is a Trojan that creates copies of itself into a targeted PC by adding a particular file. TrojanDropper:Win32/Gamarue.A creates the registry entries as part of its installation process. TrojanDropper:Win32/Gamarue.A downloads and runs files, which might be recognized as other malware infections. The downloaded file might be amember of the Win32/Gamarue family of malware. TrojanDropper:Win32/Gamarue.A checks if the Kaspersky program 'avp.exe' is running in the compromised PC. If it is, then TrojanDropper:Win32/Gamarue.A downloads the file using the file name '\$MSI\~msiexec.exe', where $ indicates a concealed folder. TrojanDropper:Win32/Gamarue.A might do this to strive to pose as a Microsoft file.

File System Details

TrojanDropper:Win32/Gamarue.A may create the following file(s):
# File Name Detections
1. \$MSI\~msiexec.exe
2. %TEMP%\07.tmp

Registry Details

TrojanDropper:Win32/Gamarue.A may create the following registry entry or registry entries:
HKEY_CURRENT_USER\SOFTWARE\"e_magic" = "[binary data]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft "[random hexadecimal number]" = "p...."

Trending

Most Viewed

Loading...