Blu-Ray and the HD DVD wars are in full swing
Spread the word
del.icio.us Digg Furl Reddit Ask BlinkList blogmarks Google Ma.gnolia RawSugar Rojo Shadows Simpy Socializer Spurl Wists Yahoo!
del.icio.us Digg Furl Reddit Ask BlinkList blogmarks Google Ma.gnolia RawSugar Rojo Shadows Simpy Socializer Spurl Wists Yahoo!
SYMANTEC REPORTED RECENTLY ON A Tojan horse that mimics the Microsoft I Windows activation interface. Called trojan.Kardphisher, it doesn’t do most of the technical things that Trojans usually do: It’s purely a social-engineering attack, aimed at stealing credit card information.
In a sense, it’s a standalone phishing program. Once you reboot, Kardphisher asks you to reactivate your copy of Windows, citing piracy issues at and telling you that another user has activated your copy. Though it assures you that you will not actually be charged, it asks for credit card information. If you don’t enter the credit card information, Kardphisher shuts down the PC.
The Trojan also disables the Windows Task Manager, which makes it more difficult to shut the malware down.
Running on the first reboot is clever. It makes the process look more like a legitimate message coming from Microsoft, and it won’t seem to occur as a result of the user clicking on a new file. The program even runs on versions of Windows that were made prior to XP and do not require activation. That’s a bit of a red flag, although I bet there’s a strong correlation between people running pre-XP versions of Windows and people who aren’t as well educated about malware as they could be.
With a nearly 1MB executable. Kardphisher is not a sneak attack. But if you find yourself infected, disable the Trojan in Windows Safe mode by removing the Registry keys described in Symantec’s write up (at www.symantec.com. search on the malware name) and deleting the program they point to. Updated anti-virus software should also remove it.
del.icio.us Digg Furl Reddit Ask BlinkList blogmarks Google Ma.gnolia RawSugar Rojo Shadows Simpy Socializer Spurl Wists Yahoo!