The current theory of operation for this virus is that it places a WDEF resource into the invisible System file Desktop. The Finder then uses this counterfeit definition to draw its windows allowing the virus to do its damage.
It also seems to be specifically designed to bypass the detection schemes used by Vaccine and GateKeeper.