Upon execution, this memory-resident backdoor drops a copy of itself as CSRRS.EXE in the Windows system folder.
Using random TCP ports, it connects to a specific Internet Relay Chat (IRC) server to receive commands from a remote user. The said commands are executed locally on the affected computer, effectively compromising its security.
It uses a predefined list of user names and passwords to log on to target computers.
In addition, it terminates processes, which are mostly related to antivirus applications ans security programs. It also launches denial of service (DoS) attacks using different flooding methods.