This Trojan may be downloaded from remote sites by other malware.
It may be dropped by other malware.
It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself.
It drops files/components. It then executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system. It is injected into processes running in memory.
It creates registry entries to enable its automatic execution at every system startup.
It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries.
It deletes itself after execution.