Sophos

Troj/Krepper-AI

Aliases
  • TROJ_KREPPER.AI
  • Trojan.Win32.Krepper.ae
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from July 2005 (3.95)
Protection available since 1 June 2005 20:41:55 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Krepper-AI is a multi-component startpage Trojan.

Troj/Krepper-AI may consist of a dropper which copies itself into the Windows system folder and sets the related start key in:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cassandra

Troj/Krepper-AI copies its main dropper component to the Windows system folder with a filename consisting of 10 to 14 random characters (including digits, excluding the letter "a") followed by THD and with an EXE extension.

Troj/Krepper-AI sets the following entry in the registry to run the main dropper component on system startup, resetting this value repeatedly:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Control handler

Troj/Krepper-AI may also set registy entries under the following:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer