TROJ_GAMARUE.ITK
March 27, 2013
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives via removable drives. It arrives as a component bundled with malware/grayware packages.
TECHNICAL DETAILS
File Size:
3,603 bytes
File Type:
None
Memory Resident:
Yes
Initial Samples Received Date:
20 Mar 2013
Arrival Details
This Trojan arrives via removable drives.
It arrives as a component bundled with malware/grayware packages.
Download Routine
This Trojan saves the files it downloads using the following names:
- %System Root%\Temp\TrustedInstaller.exe
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
NOTES:
This is the ini file that is used by the GAMARUE malware family.