To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.
Malware Overview
This worm may arrive as an attachment to email messages. It drops copies of itself and its DLL components in the current user's profile and Windows system folders. The said .DLL files are also detected by Trend Micro as WORM_AUTORUN.BT
It creates registry entries to enable its automatic execution at every system startup. It also modifies a certain registry entry as part of its installation routine.
It drops copies of itself in all removable drives. It also drops an
AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
More...