MyAntiSpyware


Fake Windows Sites + WMF Explot + Keyloger = New Botnet

Myantispyware team March 13, 2006    

Adam Piggott of Proactive Computing received message from Microsoft. The email had a link to a supposed Windows update site, but, in fact, the link went to a site running the WMF exploit. On an unpatched Windows computer, the exploit hits immediately. Social engineering is also at work, urging users to click a link at the site to get Windows updates. Either way, unpatched, or patched and clicking the link, a user gets hit with a trojan downloader; in this case the trojan file name is wusetup.exe.

The trojan downloader pulls more malware that turns the infected machine into a proxy server and makes it part of a botnet hosted on Russian servers. The trojan also downloads a keylogger, winldra.exe, also known as W32/Dumaru and Srv.SSA-KeyLogger. This keylogger is writing information stolen from infected machines to a log on a remote server

For more details on this current exploit and botnet, see SunbeltBLOG’s blog, which includes screenshots of the fake Windows update site and live botnet on the Russian server. Note – the trojan downloader file wusetup.exe is currently detected by less than half the antivirus scanners at VirusTotal

Exploits & Vulnerabilities Identity Theft Worms

 Previous Post

Trojan Horse keylogger steal end-user information for popular online games.

Next Post 

How to remove BraveSentry

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

SlimTide Reviews, Fake “$1 Baking Soda Recipe” Scam Exposed, Oprah & Dr. Ania Jastreboff?
Melt Drops Review: Scam or Legit? What You Need to Know
CartRelief.com Reviews, Scam or Legit, Uncovering the Truth!
JellyThin Reviews, Fake “Pink Gelatin” Trick Scam Exposed, Jillian Michaels?
Bariatric Gelatin Trick Recipe Scam Exposed, Dr. Jennifer Ashton and Jillian Michaels?

Follow Us

Search

Useful Guides

Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
adwcleaner
AdwCleaner – Review, How to use, Comments
How to reset Google Chrome settings to default

Recent Guides

Trojan Horse keylogger steal end-user information for popular online games.
LdPinch again spammed via ICQ
BraveSentry – new rogue anti spyware
Exchange rate conversion tool load Trojan.Downloader and Trojan.Muldrop
Running as Limited User – The Easy Way to keep a system free from malware

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2026 MASW - Myantispyware.com.