Home Malware Programs Trojans TrojanDropper:Win32/Gamarue.A

TrojanDropper:Win32/Gamarue.A

Posted: August 14, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 98
First Seen: August 14, 2013
Last Seen: July 11, 2023
OS(es) Affected: Windows

TrojanDropper:Win32/Gamarue.A is a Trojan that replicates itself into an infected computer as a certain file. TrojanDropper:Win32/Gamarue.A creates the registry entries as part of its installation process. TrojanDropper:Win32/Gamarue.A drops and executes files, which might be found as other malware threats. The downloaded file might belong to the Win32/Gamarue family of malware. TrojanDropper:Win32/Gamarue.A checks if the Kaspersky program 'avp.exe' is running in the affected computer. If it is, then TrojanDropper:Win32/Gamarue.A drops the file using the file name '\$MSI\~msiexec.exe' (where $ denotes a disguised folder). TrojanDropper:Win32/Gamarue.A might do this to attempt to pass itself off as a Microsoft file.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\07.tmp File name: %TEMP%\07.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
\$MSI\~msiexec.exe File name: \$MSI\~msiexec.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft "[random hexadecimal number]" = "p...."HKEY_CURRENT_USER\SOFTWARE\"e_magic" = "[binary data]"
Loading...