W32/Spybot-CW is a peer-to-peer and network worm with backdoor Trojan functionality.
W32/Spybot-CW copies itself to Navapsvcc.exe in the Windows system folder
and creates entries in the registry at the following locations to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Video Process = Navapsvcc.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Video Process = Navapsvcc.exe
W32/Spybot-CW may create several copies of itself in a folder called
kazaabackupfiles and then set the following registry entry to enable sharing of
this folder on the KaZaA peer-to-peer network:
HKCU\Software\Kazaa\LocalContent\Dir0
W32/Spybot-CW remains resident, running in the background as a service process
and listening for commands from remote users via IRC channels.