Analysis
Copies itself to undefinedSystemundefined/kernels88.exe.
Adds the following value:
System="undefinedSystemundefined/kernels88.exe"
to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the trojan runs everytime Windows is restarted.
Modifies the firewall configuration to add the trojan to the list of allowed programs in order to make sure that the trojan can pass through.
Downloads malicious files from the following URLs:
- http://traffstats.{REMOVED}/pic/tool.jpg
- http://traffstats.{REMOVED}/pic/search.jpg
- http://traffstats.{REMOVED}/test.php?adv=XXX
- http://traffstats.{REMOVED}/pic/tibs.jpg
- http://traffstats.{REMOVED}/pic/proxy.jpg
- http://traffstats.{REMOVED}/adv/150/adload.php?a1=XXX
- http://traffstats.{REMOVED}/dl/adv150.php?adv=XXX
- http://traffstats.{REMOVED}/pic/winlogon.jpg
It then saves and executes them.