Business News for Technology Decision-Makers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Business Briefing E-Commerce Small Business Tech Trends More Topics...
Network Security
Average Rating:
Rate this article:  
New Trojan Mimics Windows Reactivation New Trojan Mimics Windows Reactivation
By Barry Levine
May 7, 2007 11:04AM

Bookmark and Share
Symantec said that the Windows-reactivation Trojan, formally called Trojan.Kardphisher, affects Windows XP, Windows 2000, Windows Server 2003, and even earlier versions of Windows, including 95, 98, and NT. If users proceed with the Trojan reactivation, a screen appears designed to capture credit card details from unsuspecting users.
 


A new Trojan Horse is making the rounds, impersonating Windows Relevant Products/Services reactivation and antipiracy messages with the goal of duping users into divulging their credit card information.

According to computer security firm Symantec, the Trojan, dubbed Trojan.Kardphisher, creates a Windows look-alike screen, headlined "Microsoft Relevant Products/Services piracy control," and indicates that the copy Relevant Products/Services of Windows was activated by another user and needs to be reactivated.

"To help reduce software piracy, please reactivate your copy of Windows now," it instructs. "You must activate Windows before you can continue to use it." The user is given two choices: reactivating Windows over the Internet immediately or doing it later. No other applications can be run, and Task Manager cannot be launched to force-quit the Trojan.

Yes or No?

If reactivation is deferred, the system Relevant Products/Services is shut down. And if users proceed with the fake reactivation, a second screen appears, requesting private information that includes location, contact information, a credit card number, the card's expiration date and three-digit security number, and even an ATM PIN.

The Trojan informs the user that the credit card information will not be charged. But, once entered, the information is sent to the fraud's perpetrators to use as they wish. The initial screen even references an actual Microsoft antipiracy site: microsoft.com/piracy.

Symantec said that the Trojan affects Windows XP, Windows 2000, Windows Server 2003, and even earlier versions of Windows, including 95, 98, and NT.

Sometimes, Windows does indeed require reactivation, such as after substantial hardware Relevant Products/Services upgrades, but Microsoft does not ask for financial information. The Trojan's request for reactivation and its close resemblance to actual Windows screens make it a potentially effective attack against some users, Symantec said.

While Symantec has posted detailed instructions on how to remove the Trojan, some observers have noted that fake information can be entered to "activate" an infected Windows machine when prompted, so that the Trojan could then be removed.

Trust No One

"This Trojan teaches us all a good lesson -- Trust No One," wrote Symantec's Takashi Katsuki on the company's blog. "Sometimes the creators of Trojans attempt to impersonate Microsoft, a bank, or even a government organization. Whatever the warning or message says, we must make very sure it is genuine before giving up any personal details, financial or otherwise."

It is far better to doubt a genuine request until proper verification is provided, Katsuki went on to say, than it is to blindly place your trust in a message simply because it appears to have come from a trusted source.

"Sad though it may be," Katsuki wrote, "the days of leaving your front door unlocked are over. In these times, we not only need a lock on the door, we need a security guard watching the front door, the back door, and everywhere in between."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Mobile Enterprise Spotlight
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Business
Home/Top News | Business Briefing | E-Commerce | Small Business | Tech Trends | Mobile Industry News | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.