Sophos

Troj/Krepper-M

Aliases
  • Trojan-Downloader.Win32.Small.ka
  • Downloader-JH
  • TROJ_SMALL.KR
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 4 March 2005 21:43:09 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Krepper-M is a downloading Trojan for the Windows platform.

Troj/Krepper-M copies itself to a subfolder of the Windows system folder named "services" and creates the following registry entries to run itself automatically on log-on:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
xpsystem
<filename>

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
xpsystem
<filename>

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
run
<filename>

Troj/Krepper-M also adds the following entry to the System.ini configuration file to run itself automatically:

[Windows]
load = <filename>

(where <filename> is the full path to the Trojan executable)

Troj/Krepper-M downloads several configuration files from preconfigured URLs. The contents of these files determine how the Trojan behaves next. They can instruct it to:
download more files
create registry entries
execute arbitrary commands
add domains to the "trusted" list
open specific URLs in Internet Explorer

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer