This worm spreads via file-sharing networks. The worm itself is a Windows PE EXE file approximately 770KB in size, written in MS Visual Basic.
VB.b (McAfee)W32.Alcra.C (Symantec)Trojan.FakeSetup (Doctor Web)W32/Alcra-B (Sophos)WORM_VB.AQ (Trend Micro)Worm/VB.an.1 (H+BEDV)Win32.Worm.VB.AN (SOFTWIN)Worm.Alcan.D (ClamAV)W32/Imagrayd.A.wom (Panda)Win32/VB.NBR (Eset)
winupdates.exe
percentSystempercentszip.dll