This file infector may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.
This file infector modifies registry entries as part of its installation routine.
This file infector drops a copy of itself in all physical and removable drives as ZPHARAOH.EXE. It also drops an AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed.
This infector file searches for target files in certain folders. It does not infect files in the WINDOWS folder. It also searches and infects random EXE files. Infected files are detected by Trend Micro as PE_MABEZAT.B.