This worm may be downloaded from certain remote sites. It may be installed manually by a user.
It drops copies of itself. It injects threads into normal processes.
It creates registry entries to enable its automatic execution at every system startup. It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries.
It creates and modifies registry key(s)/entry(ies) as part of its installation routine.
It drops copies of itself in all physical drives and in all removable drives.
It downloads an updated copy of itself from certain Web sites. It saves the downloaded files using certain file names.
More...