This Trojan may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself.
It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries.
It gives a malicious user administrative rights to load executable codes into kernel mode where device drivers are run. This routine also allows a malicious user to install malicious codes into a system without being subjected to normal Windows security restrictions. Hence, malicious files can be downloaded regardless of the security settings.
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
More...