This worm may be downloaded from remote sites by other malware. It may arrive via network shares. It may be hosted on a Web site and run when a user accesses the said Web site.
It drops copies of itself.
It disables Windows Firewall settings.
It propagates by searching the network for certain shares, into which it attempts to drop copies of itself.
It takes advantage of the following software vulnerabilities to propagate across networks:
- Microsoft Security Bulletin MS03-026
- Microsoft Security Bulletin MS03-039
- Microsoft Security Bulletin MS03-049
It also propagates by dropping copies of itself in all available physical and removable drives. It then drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
It opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system.
It accesses Web sites to download files. As a result, malicious routines of the downloaded files may be exhibited on the affected system.