This worm spreads on the hard disk of the victim machine and to write-accessible network resources. It is a Windows PE EXE file. Modifications of this program may vary in size from 26KB to 129KB. The program may be packed with a range of packers.
When launched, the worm copies its executable file as follows:
In order to ensure that the worm is launched automatically when the system is rebooted, it registers its executable file in the system registry:
[HKCUSoftwareMicrosoftWindowsCurrentVersionRun] "Svcshare" = "%System%driversspoclsv.exe" [HKLMSoftwareMicrosoftWindowsCurrentVersionRun] "Svcshare" = "%System%driversspoclsv.exe"