When run, Worm:Win32/Gamarue.N checks if you have the file desktop.ini in your PC.
If you do, this worm reads data from the file and runs it as code. This action is done as part of the spreading mechanism on removable drives used by Worm:Win32/Gamarue.N.
The file desktop.ini might be detected as Worm:Win32/Gamarue.O.
For more information about the Worm:Win32/Gamarue family, see the description elsewhere in the encyclopedia.
Analysis by Ray Roberts
The following could indicate that you have this threat on your PC:
- You have the file desktop.ini in your PC