{"id":72533,"date":"2011-08-01T11:20:53","date_gmt":"2011-08-01T11:20:53","guid":{"rendered":"https:\/\/localhost\/wordpress\/?p=72533"},"modified":"2011-08-01T11:20:53","modified_gmt":"2011-08-01T11:20:53","slug":"trojanbanker-activator-a-fake-windows-activation","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/trojanbanker-activator-a-fake-windows-activation\/","title":{"rendered":"&#8220;TrojanBanker.Activator.a&#8221; Fake Windows Activation"},"content":{"rendered":"<p>A new infection has been spreading on the Internet targeting Windows users. In fact, it is a Trojan horse that pretends to be a Windows Activation program. Once infected, you will receive a professional looking screen simulating Microsoft Windows Activation which will state that you need to re-activate your Windows OS. The program will also ask you to enter your name, contact information and credit card details. Revealing your credit card information is a huge mistake as you will end up losing your money.<\/p>\n<p>Here is the warning message that appears, which says your copy of Windows OS was activated by another user and then asks for your billing details to check the authenticity.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/WA1.JPG\" alt=\"\" width=\"644\" height=\"507\" \/><\/p>\n<p>If you select the option &#8220;No, I will do it later&#8221; nothing happens so you are forced to click on the first option.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/WA2.JPG\" alt=\"\" width=\"645\" height=\"508\" \/><\/p>\n<p>Once infected, the file is located in %APPDATA% with the name &#8220;services.exe&#8221;.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/WA6.JPG\" alt=\"\" width=\"640\" height=\"480\" \/><\/p>\n<p>If you try to terminate this fake Windows Activator you get a BSoD (Blue Screen of Death).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/WA4.JPG\" alt=\"\" width=\"576\" height=\"433\" \/><\/p>\n<p>The Trojan will not give up until you enter your private data there and as soon as you give access to your bank account your credit card will be charged.<\/p>\n<p><a href=\"https:\/\/www.quickheal.com\/\">Quick Heal<\/a> detects this malware as <strong>TrojanBanker.Activator.a<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new infection has been spreading on the Internet targeting Windows users. In fact, it is a Trojan horse that pretends to be a Windows Activation program. Once infected, you will receive a professional looking screen simulating Microsoft Windows Activation which will state that you need to re-activate your Windows OS. The program will also [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,75],"tags":[49,73,25,47,40],"class_list":["post-72533","post","type-post","status-publish","format-standard","hentry","category-malware","category-microsoft-windows","tag-malware","tag-microsoft-os","tag-phishing","tag-security","tag-trojan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72533"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=72533"}],"version-history":[{"count":0,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72533\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=72533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=72533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=72533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}