• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

Fake Windows Sites + WMF Explot + Keyloger = New Botnet

Myantispyware team March 13, 2006    

Adam Piggott of Proactive Computing received message from Microsoft. The email had a link to a supposed Windows update site, but, in fact, the link went to a site running the WMF exploit. On an unpatched Windows computer, the exploit hits immediately. Social engineering is also at work, urging users to click a link at the site to get Windows updates. Either way, unpatched, or patched and clicking the link, a user gets hit with a trojan downloader; in this case the trojan file name is wusetup.exe.

The trojan downloader pulls more malware that turns the infected machine into a proxy server and makes it part of a botnet hosted on Russian servers. The trojan also downloads a keylogger, winldra.exe, also known as W32/Dumaru and Srv.SSA-KeyLogger. This keylogger is writing information stolen from infected machines to a log on a remote server

For more details on this current exploit and botnet, see SunbeltBLOG’s blog, which includes screenshots of the fake Windows update site and live botnet on the Russian server. Note – the trojan downloader file wusetup.exe is currently detected by less than half the antivirus scanners at VirusTotal

Exploits & Vulnerabilities Identity Theft Worms

 Previous Post

Trojan Horse keylogger steal end-user information for popular online games.

Next Post 

How to remove BraveSentry

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

Electromagnetic Anti-Freezing Car Snow Removal Device Reviews, Fake “Melt Snow in 10 Seconds” Scam Exposed
SenturaCoffee.com’s Scam: How to Identify Fake Online Deals
Remove Trustedspotsearch.com Redirect: Chrome, Edge, Firefox
Your System Is Locked Due To Detected Threats Pop-Up Scam, What You Need to Know
How to remove Olyjuk.co.in pop-up ads

Follow Us

Search

Useful Guides

remove chrome extension
How to remove Chrome extensions installed by enterprise policy
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
adwcleaner
AdwCleaner – Review, How to use, Comments
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide

Recent Guides

Trojan Horse keylogger steal end-user information for popular online games.
LdPinch again spammed via ICQ
BraveSentry – new rogue anti spyware
Exchange rate conversion tool load Trojan.Downloader and Trojan.Muldrop
Running as Limited User – The Easy Way to keep a system free from malware

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.