Unknown processes started in the background.
This malware downloads and runs executables in the background. It can come disguised in many forms. For example it can pretend to be an installer for a toolbar or for a codec. Many variants of it can be found on the Gnutella2 P2P network. Upon running it contacts the master server, downloads and executes an updated version of it (if one exists) and then starts to download and execute files from links which are hardcoded in it in encrypted format. The downloading is started even before the user clicks the accept button for the license.