It is a network-aware worm that runs a HTTP proxy on the infected computer.
Launches a thread that generates random IP addresses.
It attempts to copy itself to the following locations for each generated IP address, using a predefined list of user names and passwords.
Opens an HTTP proxy on a range of random ports.
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "Testing 123" = "%System%\msdata.dat"