This Trojan may be downloaded from remote site(s) by the following malware:
It may be downloaded unknowingly by a user when visiting malicious Web site(s).
This Trojan creates a registry key(s)/entry(ies) as part of its installation routine.
It connects to a Web site to download a non-malicious file.
It also connects to several URLs. The said URLs collect information from the affected system such as IP addresses and DNS settings. It also sends email messages to a list of addresses taken from the predefined servers using its own Simple Mail Transfer Protocol (SMTP) engine.
This routine may be used by other malware since having their own SMTP engine no longer requires using other email applications such as MS Outlook.