Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 1 June 2005 20:41:55 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Krepper-AI is a multi-component startpage Trojan.
Troj/Krepper-AI may consist of a dropper which copies itself into the Windows system folder and sets the related start key in:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cassandra
Troj/Krepper-AI copies its main dropper component to the Windows system folder with a filename consisting of 10 to 14 random characters (including digits, excluding the letter "a") followed by THD and with an EXE extension.
Troj/Krepper-AI sets the following entry in the registry to run the main dropper component on system startup, resetting this value repeatedly:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Control handler
Troj/Krepper-AI may also set registy entries under the following:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
