Well, here is Symantec's write up of this one. It lists the REgistry key in the Run portion this spam relay trojan sets up.
Check it out.