This worm arrives as attachment to email messages spammed by another malware or a malicious user. It is downloaded from remote sites by other malware.
It creates the certain registry entries to enable its automatic execution at every system startup. It also drops the following copy of itself in the Windows Common Startup folder to also enable its automatic execution at every system startup.
It propagates via email. It gathers target email addresses from files with certain file name extensions.
It utilizes a stealth mechanism that makes use of the familiar Windows folder icon for its dropped copies. The said action tricks the user into thinking that the dropped malicious files are valid and harmless folders that can be executed without fear. Once these fake folders are clicked, this worm opens the My Documents folder to hide its execution.
It modifies the affected system’s registry to disable critical services such as Registry Editor and command prompt. It hides files and extension names. It also restarts the system upon detection of certain strings in the title bar of any active window. It also removes the Folder Options item in the Tools drop-down menu from the main menu bar of Windows Explorer and Control Panel.