This Trojan may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be installed manually by a user. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself.
It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries.
It modifies registry entries to hide files with both System and Read-only attributes. It modifies registry key(s)/entry(ies) as part of its installation routine.
It uses an icon to trick users into thinking that it is a legitimate application. It bears the icon of files related to certain applications. It does the said routine to avoid easy detection and consequent removal.
More...