• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

Fake Windows Sites + WMF Explot + Keyloger = New Botnet

Myantispyware team March 13, 2006    

Adam Piggott of Proactive Computing received message from Microsoft. The email had a link to a supposed Windows update site, but, in fact, the link went to a site running the WMF exploit. On an unpatched Windows computer, the exploit hits immediately. Social engineering is also at work, urging users to click a link at the site to get Windows updates. Either way, unpatched, or patched and clicking the link, a user gets hit with a trojan downloader; in this case the trojan file name is wusetup.exe.

The trojan downloader pulls more malware that turns the infected machine into a proxy server and makes it part of a botnet hosted on Russian servers. The trojan also downloads a keylogger, winldra.exe, also known as W32/Dumaru and Srv.SSA-KeyLogger. This keylogger is writing information stolen from infected machines to a log on a remote server

For more details on this current exploit and botnet, see SunbeltBLOG’s blog, which includes screenshots of the fake Windows update site and live botnet on the Russian server. Note – the trojan downloader file wusetup.exe is currently detected by less than half the antivirus scanners at VirusTotal

Exploits & Vulnerabilities Identity Theft Worms

 Previous Post

Trojan Horse keylogger steal end-user information for popular online games.

Next Post 

How to remove BraveSentry

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

Dr. Emma Clark Pumpkin Seed Recipe Review, Gut Drops – Weight Loss Scam?
CrazyLeaf SMGT-GLP-1 Nano Microneedle Patch Review, Scam or Legit? What You Need to Know
scam alert
Retro Revive Chrome extension (Virus removal guide)
scam alert
DesignHub malicious extension (Virus Removal Guide)
Vital Breeze AC Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]
How to reset Mozilla Firefox (Updated Apr. 2018)
remove chrome extension
How to remove Chrome extensions installed by enterprise policy

Recent Guides

Trojan Horse keylogger steal end-user information for popular online games.
LdPinch again spammed via ICQ
BraveSentry – new rogue anti spyware
Exchange rate conversion tool load Trojan.Downloader and Trojan.Muldrop
Running as Limited User – The Easy Way to keep a system free from malware

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.