Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Windows activation Trojan can catch the unwary  (Read 4265 times)

0 Members and 1 Guest are viewing this topic.

honvetops

    Topic Starter


    Specialist
  • Hardware rocks ~
  • Thanked: 8
    Windows activation Trojan can catch the unwary
    « on: May 07, 2007, 06:18:35 AM »

    Watch out – the bad guys have stepped up their Trojan creation nastiness by creating Trojans that look like real Windows alerts which wouldn’t fool experts but could easily catch novices.

    Given Microsoft’s well publicized anti-piracy drives, some novice to intermediate users might easily be fooled by a new Trojan horse called “Trojan.Kardphisher” which opens up a relatively realistic looking “Microsoft Piracy Control” dialog box.

    Symantec says that Trojan.Kardphisher is a “Trojan horse that attempts to steal credit card numbers by tricking the user into entering their credit card details to activate Windows”.

    Frighteningly, if a user falls victim to this Trojan, the rogue software will shut down Windows should the user choose to “activate” their copy of Windows later, something that would easily spook novice and intermediate users into entering their details when they next turn their computer on, because the Trojan instantly activates itself again and prevents you from running other software.

    The Trojan, which you can see 'screen 1' of here, and then 'screen 2' of here, is incredibly brazen. Once you choose to “activate” your copy of Windows because the Trojan tells you that “Your copy of Windows was activated by another user”, it asks you to enter in your location, your contact information, your credit card number, your ATM pin number (!), your card’s expiration date and the 3-digit CVV2 number.

    The software tells you that your card won’t be charged, but that it needs the details to proceed with activation.

    Naturally, if you divulge your real details, they are sent off to the author of the Trojan, who can then use them to steal your identity, rack up credit card debts and do other nasty things.

    One suggestion from the web on dealing with the Trojan should you find yourself infected with it is to simply enter in fake details, simply so that you can get past the “activation” process and immediately find out how to remove the Trojan from your system. Thankfully, Symantec have posted removal instructions which tell you how to get rid of the Trojan.

    If a user does choose to run Windows over the web, the trojan asks the victim to enter location, contact information, credit card number, PIN and card expiration date.

    It’s important to know that Microsoft and other companies will NOT ask you to enter credit card details and other information for the simple purpose of activating software. Of course, you will be asked for some personal information if you are registering software you have just purchased, and we may well see attempts by the ‘bad guys’ to now create registration Trojans that look ever more realistic.

    The attempts at ‘social engineering’ to get you to voluntarily hand over sensitive private details are only going to increase, making it ever more imperative that users become ultra web-savvy, as well as protected as much as possible by Internet Security Suites from companies such as Symantec, McAfee, Trend Micro, ZoneAlarm, AVG and others, along with protective anti-phishing software such as TrustDefender www.trustdefender.com.

    If ever in doubt – err on the side of caution and never enter your real details. Get the help of a knowledgeable friend, call the tech support department of the software or hardware you are using, ask questions – don’t just hand over personal details that could expose you to identity theft, fraud and more – and make sure that you are using the very latest security programs and make sure their automatic update features are permanently turned on.

    http://www.itwire.com.au/content/view/11853/1103/
    mobo- MSI P6N SLI / LCD Samsung  226BW
    Ram- G-Skill dual HQ / Speakers- 5300e's
    Fatality Hi-Fi Soundcard
    cpu - currently ~ E6600 / Foxfire only
    dual~Seagate 320 gig sata's
    8800 gts- MSI /Verizon Fios
        news is knowledge

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: Windows activation Trojan can catch the unwary
    « Reply #1 on: May 07, 2007, 06:28:08 AM »
    Quote
    “Trojan horse that attempts to steal credit card numbers by tricking the user into entering their credit card details to activate Windows”
    Won't fool me. Might fool newbies though...

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: Windows activation Trojan can catch the unwary
    « Reply #2 on: May 07, 2007, 07:17:52 AM »
    I think you'd have to be pretty dense to get duped by this one, but I've seen worse.  In any case, thanks for the info.
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey

    unlovedwarrior



      Guru

    • someday this name will be known
    • Thanked: 13
      Re: Windows activation Trojan can catch the unwary
      « Reply #3 on: May 07, 2007, 08:27:43 AM »
      crap... i better warn my family. they might just fall for it