When executed, the trojan copies itself in the following location:

Program Files\Internet Explorer\PLUGINS\

The following file is dropped in the same folder:


Size of the file is approximately 40 kB. The following Registry entries are set:

default = "c:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys"
"ThreadingModel" = "Apartment"


"First" = "wk"


Code of the trojan is injected in running processes.

Information stealing

The trojan collects various information when QQ Instant Messenger is being used. The trojan can send the information to a remote machine. The HTTP protocol is used.