0 0
This Trojan program downloads files via the Internet without the user's knowledge or consent.
The Trojan itself is a Windows PE EXE file approximately 6KB in size, packed using FSG. The unpacked file is approximately 49KB in size.
Once launched the Trojan creates a file named "kernels64.exe" in the Windows system directory:
%System%\kernels64.exe
It then registers this file in the system registry, ensuring that the Trojan will be launched each time Windows is rebooted on the victim machine:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "System" = "%System%\kernels64.exe"
This Trojan will download, install and launch for execution other malicious programs (Pornware) on the victim machine.

Subscribe
Hot Articles