Selected viruses, spyware, and other threats: sorted alphabetically
When executed, the trojan copies itself in the following location:
The following file is dropped in the same folder:
Program Files\Internet Explorer\PLUGINS\system2.jmp
Size of the file is approximately 40 kB. The following Registry entries are set:
default = "c:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys"
"ThreadingModel" = "Apartment"
"First" = "wk"
Code of the trojan is injected in running processes.
The trojan collects various information when QQ Instant Messenger is being used. The trojan can send the information to a remote machine. The HTTP protocol is used.