Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 14 May 2007 23:44:32 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/KardPhis-A is a Trojan for the Windows platform.
When run, Troj/KardPhis-A displays a fake message pretending to be from Microsoft. It informs the user that their copy of Microsoft needs to be reactivated to prevent piracy and that they will need to enter their credit card details for the same. These details are then mailed off to a website.
If the user chooses not to go ahead with this, the system is shut down.
When Troj/KardPhis-A is installed it creates the file <Pathname of Trojan executable>\keylog.dll. This file is also detected as Troj/KardPhis-A.
The following registry entry is created to run Troj/KardPhis-A on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
soft2
<pathname of the Trojan executable>
The following registry entry is set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
