Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 13-05-2007, 08:59 PM   #1 (permalink)
HELP AND SUPPORT
 
rakeshishere's Avatar
 
Join Date: Jun 2006
Posts: 1,603
Default Microsoft Confirms the Windows Activation Trojan Horse


Quote:
Microsoft has confirmed Symantec reports related to the spreading of a Windows product activation Trojan horse. The malicious code, identified by the Cupertino-based company as Trojan.Kardphisher, is designed to attack Windows XP users, by masquerading as Microsoft's Windows Genuine Advantage tool.

According to Symantec, the malicious code in itself is only a minor threat, but the problem resides in the fact that the Trojan asks users to enter their credit card credentials. The social engineering aspect of this attack is quite well thought out and put together, as you will be able to see from the video embedded at the bottom, courtesy of Symantec.

"While not a technically sophisticated approach, this Trojan relies on a social engineering tactic to trick consumers into providing credit card and other personal data. Because of situations like this Microsoft recommends that people be very cautious about revealing personal and financial information online," revealed Alex Kochis, senior licensing manager on the WGA team.

Symantec's Takashi Katsuki posted the following instructions detailing the process users need to undertake to remove Trojan.Kardphisher:

1. Reboot the infected machine. You can do that by simply clicking the "No" and "Next" buttons,
or by doing a good-old fashioned hard reboot.
2. While Windows is starting, press the function 8 key (F8 key) to enter Safe Mode.
3. Click Start > Run.
4. Type regedit
5. Click OK.
6. Navigate to and delete these subkeys:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRunsoft2
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionPoliciesSystemDisableTaskMgr
(If it exists)
7. Exit the Registry Editor.

Users also have the possibility to introduce fake information in order to access their computer. You will be able to enter virtually any combination of letters and numbers for the email address, phone number, expiration date, credit card number, CVV2 code, ATM PIN and name on card, as long they resemble genuine ones. Next, make your way to this registry key:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRunsoft2.
SOURCE
rakeshishere is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 13-05-2007, 11:55 PM   #2 (permalink)
Alpha Geek
 
sam_1710's Avatar
 
Join Date: May 2006
Posts: 755
Default Re: Microsoft Confirms the Windows Activation Trojan Horse

already posted by tech here!!
http://www.thinkdigit.com/forum/showthread.php?t=57628 - he's posted it alond wid a Video demonstration!!
sam_1710 is offline  
Old 14-05-2007, 09:51 AM   #3 (permalink)
HELP AND SUPPORT
 
rakeshishere's Avatar
 
Join Date: Jun 2006
Posts: 1,603
Default Re: Microsoft Confirms the Windows Activation Trojan Horse

Quote:
Originally Posted by sam_1710
already posted by tech here!!
http://www.thinkdigit.com/forum/showthread.php?t=57628 - he's posted it alond wid a Video demonstration!!
rakeshishere is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Impersonates Windows Activation to Snatch Data Digit_Dragon Technology News 4 03-08-2007 12:50 PM
Trojan Horse Deactivates Genuine Windows Copies! Third Eye Technology News 21 07-05-2007 12:24 PM
Microsoft Confirms: No Big Bang Service Pack 1 for Windows Vista Third Eye Technology News 7 02-04-2007 04:23 PM

 
Latest Threads
- by Krow
- by Tenida
- by iGamer
- by abhidev
- by icebags

Advertisement




All times are GMT +5.5. The time now is 01:08 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2