Threat Information for "Win32.HLLW.Krepper"

Removal Top

StopSign will automatically remove this infection with a paid membership.

Summary Top
  • Name: Win32.HLLW.Krepper
  • Aliases:
  • Date Discovered: 2007-01-11
  • Protection Added: 2007-01-25
Description Top
-- Ease of Removal

1: Uses running processes
2: Consistently named
3: Consistent file contents
4: Creates new registry entries with consistent data

-- Privacy Risks/Security Changes

1: Mimics legitimate file names
2: Transmits personal data to remote computers

-- Damage/Intrusion/Annoyance

1: Significantly slows down the computer
2: Downloads other threats
3: Creates new files

-- Propagation/Saturation

1: Spreads to other computers on the same network
2: Spreads through Peer-2-Peer software
3: Infects from a link in an email
4: Infects from an email attachment
5: Installed by other infections
Technical Details Top
  • Added Directory/File:
    FilePath: %ROOTDRIVE%window\system32\sndcfg16.exe
  • Added Directory/File:
    FilePath: %TEMPDIR%\???.bat
  • Added Registry Value:
    Key: HKLM\%CURRENTVERSIONREG%\RunServices Value: WinProfile
  • Added Registry Value:
    Key: HKLM\%CURRENTVERSIONREG%\Run Value: WinProfile