To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

Malware Overview
This file infector spreads by infecting running processes that use .EXE and .SCR extensions. It checks whether the target processes are files that are of portable executable (PE) format. It then appends its code to infect target processes. It avoids processes and files with certain strings in their file names.
In addition, this file infector has backdoor capabilities. It opens port 65520 and connects to a specific Internet Relay Chat (IRC) server. Once connected, it assigns itself a specific nick and allows a remote user to download files into the affected system. This routine effectively compromises the affected system’s security.