Sophos

Troj/KardPhis-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from July 2007 (4.19)
Protection available since 14 May 2007 23:44:32 (GMT)
Detected by All Sophos products

Action

More Information

Troj/KardPhis-A is a Trojan for the Windows platform.

When run, Troj/KardPhis-A displays a fake message pretending to be from Microsoft. It informs the user that their copy of Microsoft needs to be reactivated to prevent piracy and that they will need to enter their credit card details for the same. These details are then mailed off to a website.

If the user chooses not to go ahead with this, the system is shut down.

When Troj/KardPhis-A is installed it creates the file <Pathname of Trojan executable>\keylog.dll. This file is also detected as Troj/KardPhis-A.

The following registry entry is created to run Troj/KardPhis-A on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
soft2
<pathname of the Trojan executable>

The following registry entry is set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer