W32/Spybot-OQ is a worm for the Windows platform.
When run W32/Spybot-OQ copies itself to
<Windows>\System\svhost.exe
and creates the file
<System>\drivers\sysdrv32.sys - detected as W32/Rbot-GXM
W32/Spybot-OQ sets the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WSVCHO
<Windows>\system\svhost.exe
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYSDRV32\
HKLM\SYSTEM\CurrentControlSet\Services\sysdrv32\
W32/Spybot-OQ spreads via removable shared drives by copying itself to <Root>\wlan.exe and creating the file <Root>\autorun.inf - detected as W32/Spybot-OQ