W32/Clantard-A is a worm for the Windows platform.
When first run W32/Clantard-A copies itself to <System>\kchts.exe.
W32/Clantard-A also attempts to copy itself to the A: drive as setup.exe.
The following registry entry is created to run kchts.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Update
<System>\kchts.EXE %
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
RegisteredOrganization
HACKCLAN CORP.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
RegisteredOwner
SunSoft