This malicious program is a worm. It is a Windows PE EXE file. It is 67,072 bytes in size.
When launched, the worm copies its executable file to the Windows root directory:
The worm also extracts the following file from its body to its working directory:
%WorkDir%VirDll.dll – this file is 17 920 bytes in size.
The worm creates the following registry key, and save its configuration to this key: