Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: ALERTS

Spyware poses as Microsoft® Update

Date: 06/22/2009
Author: Razvan Livintz

Creates havoc, steals data and zombifies your computer

Speculating the "Downadup/Conficker lesson" that reminded (please read taught) people to continuously update their systems with the latest patches and fixes, the current malware exploits people's fears and behavioral stereotypes when dealing with computer security.

Microsoft never sends (individual) e-mails announcing the availability of a new fix, but uses its OS integrated automatic update systems - namely Windows Update or Microsoft Update. The current unsolicited message wave bears several characteristics pertaining to the Richmond-based company security bulletins, such as the general content and formatting, which could definitely trick the inexperienced user to follow the supposed update link.

Microsoft Phishing

However, upon clicking the link the user is not directed to Microsoft portal, but to a phony Web page that loads from a domain registered in Mexico. If the user clicks the download link of that alleged 80 KB Outlook/Outlook Express update, one triggers, in effect, the download of a horrific piece of spyware - Trojan.Spy.ZBot.UO.

Microsoft phishing

The newest member of the renowned ZBot family it is disguising under the innocent appearance of a .CHM (on-line help) file. Upon launching, it injects code within the winlogon.exe process in order to gain access to the main services, run stealthily on the compromised machine and freely connect to Internet.

For its spyware purposes, it creates a hidden directory within the Widnows\System32 folder, which it populates with three encrypted files. Here it stores the sensitive data it steals from the infected computer, such as log in credentials, including, but not limited to e-banking and e-mail authentication details and content, as well as on-line history. The encrypted files also hold further configuration instructions, remote control and spamming specifications.

The high rate of spreading reveals that social engineering techniques do pay back, especially during crisis, and that users' gullibility could lead to another malware pandemic.

Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

user comments
I had a windows/microsoft security update appearing each day and noticed that it always bears the same serial number. Does this mean anything? This is when I click on the yellow shield that indicates new updates are ready to install. Do I need to worry as my Bitdefender Internet Security does not update automatically, but do it manually (giving me an error).
Don't these idiots that keep writing this malicious code ever get tired of being complete a_______s? I can't beleive that people are dense enough to go for some of these ill written Trojans and viruses! They don't even look official.
My friend has forwarded such email to me
Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
bitdefender worm system microsoft data windows antivirus word messages security canadian malware files message omelette pharmacy twitter downadup infected trojan file online review conficker spam virus computer software exploit rogue