Selected viruses, spyware, and other threats: sorted alphabetically
Win32/Kardphisher.A
|
Short description
Win32/Kardphisher.A is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to fill in sensitive information. After the sensitive information is entered, the trojan removes itself from the infected computer.Installation
The trojan does not create any copies of itself.The following files are dropped into the current folder:
- keylog.dll (3072 B)
- [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion
Run]
"soft2" = %malwarepath%
- [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
PoliciesSystem]
"DisableTaskMgr" = "1"
Other information
Win32/Kardphisher.A is a trojan that blocks access to the Windows operating system. To regain access to the operating system the user is asked to fill in sensitive information.The trojan displays the following fake dialog boxes: After the sensitive information is entered, the trojan removes itself from the infected computer.
The following fields can contain arbitrary data:
- "Location"
- "Phone number"
- "Expiry date"
- "Name on card"
- @
The field "ATM PIN" must contain 4 characters.
The field "CVV2 code" must contain 3-4 characters.
The trojan attempts to send gathered information to a remote machine.
The trojan connects to the following addresses:
- 81.29.241.170/in.php
The trojan may set the following Registry entries:
- [HKEY_CURRENT_USERSoftwaresft]
"c"
"d"
The trojan interferes with the operation of some security applications to avoid detection.




