This worm is downloaded from remote sites or dropped by other malware. It can also arrive in a system via removable drives.
It propagates by dropping copies of itself in all physical and removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
It opens port 6667 where it listens for remote commands.
It connects to Internet Relay Chat (IRC) servers and joins channels.
It executes commands from a remote malicious user, effectively compromising the affected system.
It takes advantage of the following software vulnerabilities: