This backdoor arrives as a downloaded file from the Internet. It may also arrive as a downloaded file from a peer-to-peer (P2P) network.
It drops a copy of itself as SVCHOST.EXE, disguising itself as a legitimate file to avoid easy detection. It sets its attributes to hidden and system. It also displays the following fake error message, stating that the installer is corrupted:

It connects to an Internet Relay Chat (IRC) server and joins a channel by opening a random TCP port. It then waits for commands from a remote user. The said commands are executed locally, thus compromising the affected system.
This backdoor also attempts to act as a P2P server/client to enable downloading of a copy of itself by users connected to a specified P2P network.