Troj/KardPhis-A

Category: Viruses and Spyware Protection available since:14 May 2007 00:00:00 (GMT)
Type: Trojan Last Updated:14 May 2007 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/KardPhis-A is a Trojan for the Windows platform.

When run, Troj/KardPhis-A displays a fake message pretending to be from Microsoft. It informs the user that their copy of Microsoft needs to be reactivated to prevent piracy and that they will need to enter their credit card details for the same. These details are then mailed off to a website.

If the user chooses not to go ahead with this, the system is shut down.

When Troj/KardPhis-A is installed it creates the file <Pathname of Trojan executable>\keylog.dll. This file is also detected as Troj/KardPhis-A.

The following registry entry is created to run Troj/KardPhis-A on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
soft2
<pathname of the Trojan executable>

The following registry entry is set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

download Try Sophos products for free
Download now