This backdoor may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself. It drops files. It injects threads into a normal process.
It opens a hidden Internet Explorer window. It opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system.
It logs user keystrokes. It does the said routine to steal information.
It deletes itself after execution.
More...