When executed, Worm:Win32/Ramnit.A copies itself to %program_files%\microsoft\desktoplayer.exe.
Worm:Win32/Ramnit.A also creates a mutex named "KyUffThOkYwRRtgPP".
Worm:Win32/Ramnit.A launches the default web browser and injects code to it.
The injected code may be detected as Virus:Win32/Ramnit.A!dll, which contains the file infection functionality. (Refer to Virus:Win32/Ramnit.A!dll for more details)
Analysis by Chun Feng
The following system changes may indicate the presence of this malware: