Home Malware Programs Fake Warning Messages Lsas.Blaster.Keyloger

Lsas.Blaster.Keyloger

Posted: February 8, 2010

Lsas.Blaster.Keyloger (alias Lsas.Blaster.Keylogger) is a pseudo infection which gets falsely detected by Security Tool rogue anti-spyware after it compromises a computer. This malware will produce a popup alert that states: "rundll32.exe is infected with worm Lsas.Blaster.Keyloger. This worm is trying to send your credit card details using rundll.exe to connect to remote host". This is, in fact the official description of Lsas.Blaster.Keyloger which does actually exist. But if you find out about this alleged infection from a pop-up which Security Tool produces, be sure that this malware is trying to make a fool of you. When Security Tool rogue antivirus utility enters your system, it will try to get you to purchase its license by using some of these scare techniques. Therefore if you get warning messages that denote Lsas.Blaster.Keyloger worm's presence on your computer, you should terminate the source of infection, which is the Security Tool scareware application. Use a proven anti-spyware program to rid your PC this cyber menace.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\4946550101
    2 %UserProfile%\Application Data\4946550101\[random number].bat
    3 %UserProfile%\Application Data\4946550101\[random number].cfg
    4 %UserProfile%\Application Data\4946550101\[random number].exe
    5 %UserProfile%\Desktop\Security Tool.lnk
    6 %UserProfile%\Start Menu\Programs\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Security ToolHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random number]"

One Comment

Loading...