-----http://www.sophos.com/virusinfo/analyses/trojstartpabt.html--------------
[Trojan.Win32.Harnig.c]
The Trojan copies itself to reg33.exe in the Windows folder and sets the following regitry entry to ensure that the copy is run each time Windows is started: