This worm arrives via removal drives.
This worm drops the following files. A dropped component is injected into all running processes. This worm then creates the following registry entry to enable its automatic execution at every system startup:
This worm modifies registry entries to hide files with both
System and
Read-only attributes.
This worm drops copies of itself in all physical and removable drives. It also drops an
AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed.
More...