Registry Hive/Sub-Key

When the attachment is executed, the worm drops a copy of itself into the System directory. It then sets up a registry key to run itself on Windows startup: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\="C:\WINDOWS\SYSTEM\" The worm creates further copies of itself by inserting its code into .rar archives. ................
................