It removes the following registry keys and values:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TaskMon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
HKCU\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32
The worm terminates processes with names that contain any of the
following strings:
"document"
"readme"
"doc"
"text"
"file"
"data"
"test"
"message"
"body"
"taskmon"
"xsharez_scanner"
"BlackIce_Firewall_Enterpriseactivation_crack"
"zapSetup_95_693"
"MS59-56_hotfix"
"winamp0"
"NessusScan_pro"
"attackXP-6.71"
Propagation Through SoulSeek
If the infected computer has a copy of the SoulSeek file sharing
application the worm copies itself to the shared folder with
different catchy names for users to download:
"WinXPKeyGen.exe"
"Windows2003Keygen.exe"
"mIRC.v6.12.Keygen.exe"
"Norton.All.Products.KeyMkr.exe"
"F-Secure.Antivirus.Keymkr.exe"
"FlashFXP.v2.1.FINAL.Crack.exe"
"SecureCRTPatch.exe"
"TweakXPProKeyGenerator.exe"
"FRUITYLOOPS.SPYWIRE.FIX.EXE"
"ALL.SERIALS.COLLECTION.2003-2004.EXE"
"WinRescue.XP.v1.08.14.exe"
"GoldenHawk.CDRWin.v3.9E.Incl.Keygen.exe"
"BlindWrite.Suite.v4.5.2.Serial.Generator.exe"
"Serv-U.allversions.keymaker.exe"
"WinZip.exe"
"WinRar.exe"
"WinAmp5.Crack.exe"