Update: Beware of new Windows activation Trojan

09/08/2011
G DATA Blog

Another way to get rid of this malware, without the need of pc expertise. Defeat it with its own weapons!

Another analysis of the sample described in the previous blog post showed us, that the malware author left the program code door ajar for the victims.

We have publsihed a removal instruction for this threat already, but we are also able to provide you with the activation key asked for when your pc is locked. This five times five character code has been hard coded within the malware program.

By using QRT5T-5FJQE-53BGX-T9HHJ-W53YT as the activation key, the malware program starts a kind of cleaning function, which is only initiated in case of the entry of a correct key. This cleaning function will restart your computer and remove this malware from your system, almost completely. The only data that remains is harmless stuff in %TEMP%.