This worm creates several copies of itself in several directories on the affected system. It creates a file called PROFILE.VBS in the Windows installation directory. Additionally it creates the files MDM.VBS, USER.DLL, README.HTML and SYSTEM.DLL in the Windows/System folder.
In addition, it checks to see if the user name coincides with any of the following:
central intelligence agency
american stock exchang
If any of texts coincide with the affected system's user name, the worm will modify the file C:\AUTOEXEC.BAT by adding the command DELTREE C:\. With this command, the worm manages to delete all the files and folders in the C: drive.
Additionally, if the system date stamp matches 5 July, it creates a file called 75.HTM in the Windows/System folder.
Finally, the worm finds all the files with HTML extension in order to overwrite them with its code.