W32/Glupzy-B is a worm for the Windows platform.
When first run W32/Glupzy-B copies itself to:
<Startup>\systemID.pif
<System>\Flashy.exe
The following registry entry is created to run Flashy.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Flashy Bot
<System>\Flashy.exe
Registry entries are set as follows:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
2
W32/Glupzy-B copies itself to available removable drives and ramdisks, using the names of existing files with the extension changed to EXE.