W32/Gamarue-AM

Category: Viruses and Spyware Protection available since:04 Mar 2013 16:28:24 (GMT)
Type: Win32 worm Last Updated:04 Mar 2013 16:28:24 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Gamarue-AM exhibits the following characteristics:

File Information

Size
34K
SHA-1
c986939ef1baeae28d4796a65b71eb3ff0ce195a
MD5
39d14a4bb155dedfde37325cb92d12e8
CRC-32
1dfec158
File type
application/x-ms-dos-executable
First seen
2013-03-04

Runtime Analysis

Copies Itself To
  • C:\Documents and Settings\All Users\svchost.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    SunJavaUpdateSched
    C:\Documents and Settings\All Users\svchost.exe
Registry Keys Modified
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    test_item.exe

download Try Sophos products for free
Download now