This worm may be dropped by other malware. It may arrive bundled with malware packages as a malware component. It may be installed manually by a user. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself. It drops files/components. Trend Micro detects its component file as BKDR_SMALL.DDE. It then executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
It modifies registry entries to enable its automatic execution at every system startup.
It drops copies of itself in all physical and removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.