Gamarue.O contains code that is loaded and run by Gamarue.N. It might have the file name desktop.ini.
When run, it connects to a server at thesecond.in. From there, it downloads a file that it saves as thumbs.db. This file is then decrypted and saved as C:\Temp\TrustedInstaller.exe, then run.
Note that desktop.ini and thumbs.db are both file names commonly used by clean files, and most PCs have files with these names that aren't necessarily malware.
You can learn more about the Worm:Win32/Gamarue family in the family description.
Analysis by Ray Roberts
Alerts from your security software may be the only symptom.