Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

May 4th, 2007, 13:17 GMT · By

Trojan Horse Deactivates Genuine Windows Copies!

SHARE:

Adjust text size:


Trojan.Kardphisher
Enlarge picture
Trojan.Kardphisher is a Trojan horse program that deactivates genuine and previously activated copies of Windows following the infection. Security Company Symantec has warned on the spreading of
Trojan.Kardphisher, and revealed that the malicious program is not a technical masterpiece, but that it is focused on social engineering techniques. The catch is that the malicious code does not actually deactivate genuine copies of Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP, either activated or not.

After compromising a system, the malware becomes active with the first Windows boot and displays a message with the title "Microsoft piracy control" just as in the adjacent image. The Trojan informs the users that their copy was activated by another person and asks them to repeat the activation process.

It is obvious that the author of this social engineering scheme has gone to great lengths in order to make the attack look and feel as legitimate as possible, but still there are some loopholes that point to a fake. First off, Microsoft generally avoids using the term "piracy" in direct contact with Windows users, Genuine Software Initiative gives a clue as to the policies applied by the Redmond Company. And Windows Genuine Advantage is the mechanism that governs over Microsoft's detections of non-genuine copies of the operating system. Trojan.Kardphisher additionally asks for the users' billing details and offers only the possibility of activating Windows over the Internet.

"You can only choose Yes or No. You can't run Task Manager or any other applications. If you choose No your PC will be shut down immediately," said Takashi Katsuki, Symantec Security response Engineer. Choosing the Yes option will take the users to the screen captured in the image at the bottom where they will be asked for their credit card details.

Trojan.Kardphisher
Enlarge picture
"Now you may think "It can't be true. I have activated my legitimate copy of Windows. MS can't do such a thing!". Surely almost everyone will notice that something strange is going on, and hopefully very few people will actually become victims by inputting their credit card details. But unfortunately even the people who are not tempted to give up their information this time might well become victims the next time. After all, failure to follow the on-screen instructions results in your PC shutting down immediately," Katsuki added.
FILED UNDER:
Windows
Symantec
Trojan

TELL US WHAT YOU THINK:

8,115 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


The Votes Are in: Kaspersky the Best Anti-Virus for Windows Vista

Mac and Linux' Viruses Growth to Explode - Not Windows Vista's

Download Kaspersky Anti-Virus 7.0 and Kaspersky Internet Security 7.0 for Windows Vista

Firefox 2.0 and IE7 - Attack Vectors for Windows Vista

McAfee Kills Vista

READER COMMENTS:


Comment #1 by: totemT on 27 Jun 2007, 08:35 UTC reply to this comment

I don't know about trojan horses deactivating Vista, but I can tell you from experience:
I just tried the newly released Kaspersky Internet Security 7.0.123, only to discover that upon rebooting, my Vista system was de-activated.
I loaded an Acronis backup image I had made of my system before the installation of any Antivirus and firewall, and I again made a fresh installation of Kaspersky Internet Security. AGAIN, my system was de-activated by it.
If any votes are in in favor of Kaspersky, I have to wonder if they've been made by the employees of Kaspersky, if not by the management!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM