This worm may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself. It creates registry entries to enable its automatic execution at every system startup.
It disables Task Manager and Registry Tools. It does the said routine to avoid termination from the affected system's memory.It creates registry key(s)/entry(ies). It modifies registry key(s)/entry(ies) as part of its installation routine.
It drops copies of itself in physical drives. It may arrive via removable drives. It drops copies of itself in specific drives. It drops an
AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
More...