Windows Activation Trojan!

fazaal24

Member
Nov 10, 2006
33,026
18
0
Carbon Canyon Dehiwala
Some novice to intermediate users can easily be fooled by a new Trojan horse called “Trojan.Kardphisher” which opens up a relatively realistic looking “Microsoft Piracy Control” dialog box.

If a user falls victim to this Trojan, the rogue software will shut down Windows and ask the users choose to “activate” their copy of Windows and enter their details when they next turn their computer on.

Once you choose to “activate” your copy of Windows because the Trojan tells you that “Your copy of Windows was activated by another user”, it asks you to enter in your location, your contact information, your credit card number, your ATM pin number (!), your card’s expiration date and the 3-digit CVV2 number. The software tells you that your card won’t be charged, but that it needs the details to proceed with activation.

Symantec have posted removal instructions which tell you how to get rid of the Trojan.

Its interface looks really similar as all Windows XP dialogs. Here are the screenshots:
Kardphisher1sm.jpg
Kardphisher2sm.jpg
 

fazaal24

Member
Nov 10, 2006
33,026
18
0
Carbon Canyon Dehiwala
In the context of computer software, a Trojan horse is a program that unlike a virus, contains or installs a malicious program (sometimes called the payload or 'trojan') while under the guise of being something else. The term is derived from the classical myth of the Trojan Horse. Trojan horses may appear to be useful or interesting programs (or at the very least harmless) to an unsuspecting user, but are actually harmful when executed.