This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself.
It creates registry entries to enable its automatic execution at every system startup. It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating a registry entry. It modifies registry entries to enable its automatic execution at every system startup.
It drops copies of itself in all physical drives and in all removable drives. It drops an
AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
More...