W32/Nuwar-E is a worm for the Windows platform.
When run W32/Nuwar-E copies itself to the <Windows> folder and sets the following registry entry to run itself on startup.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<filename of worm>
<Windows>\<filename of worm>.exe
W32/Nuwar-E also sets the following registry entries:
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
NtpServer
time.windows.com,time.nist.gov
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
Type
NTP