About Trojan.Krepper
Krepper is a trojan virus, that modifies
website surfing to display advertising, and
downloads additional threats Will add start
autorun keys in the registry to make sure it runs
on startup.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
xp_system = c:\windows\inetper\services.exe
The xp_system Registry value keys it to Krepper.
Variants:
- Trojan.Win32.Krepper.a
- Trojan.Win32.Krepper.o
- Trojan.Win32.Krepper.p
Trojan.Krepper Removal Instruction
Automatic Removal: Using Spyware Doctor
to detect and remove Trojan.Krepper AUTOMATICALLY!
Manual Removal:
- Kill these running processes with Task
Manager:
systemroot+\system\matrixhere.exe
systemroot+\system\sysstartup.exe
systemroot+\system32\matrixhere.exe
systemroot+\system32\sysstartup.exe
trojan.win32.krepper.a.exe
trojan.win32.krepper.a_(120).exe
- Go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\jopa,
delete it and reboot the machine
immediately.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\romahere,
delete it and reboot the machine
immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\jopa,
delete it and reboot the machine
immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\romahere,
delete it and reboot the machine
immediately.
- Unregister these DLLs with Regsvr32, then reboot:
trojan.win32.krepper.o.dll
trojan.win32.krepper.p.dll
trojan.win32.krepper.p_(10).dll
- Remove these registry items (if present)
with RegEdit:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\jopa
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\romahere
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\jopa
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\romahere
- Remove these files (if present) with Windows
Explorer:
systemroot+\system\matrixhere.exe
systemroot+\system\sysstartup.exe
systemroot+\system32\matrixhere.exe
systemroot+\system32\sysstartup.exe
trojan.win32.krepper.a.exe
trojan.win32.krepper.a_(120).exe
trojan.win32.krepper.o.dll
trojan.win32.krepper.p.dll
trojan.win32.krepper.p_(10).dll
Detection and Removal Instructions for Trojans
|