{"id":8355,"date":"2016-12-08T11:57:55","date_gmt":"2016-12-08T11:57:55","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=8355"},"modified":"2018-05-29T11:55:36","modified_gmt":"2018-05-29T11:55:36","slug":"wmi-commandline-utility-malware-pop-up","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/wmi-commandline-utility-malware-pop-up\/","title":{"rendered":"WMI Commandline Utility Malware Pop Ups &#8211; Click NO!"},"content":{"rendered":"<p>I was helping out a <a href=\"http:\/\/www.freefixer.com\/b\/about-freefixer\/\">FreeFixer<\/a> user this morning, trying to track down some malware in his FreeFixer log that he sent me.<\/p>\n<p>While searching for information about a .DLL file, I found a spam post on\u00a0imgur.com, which linked to another web page that started a download of an executable file.<\/p>\n<p>And this one is pretty nasty. Look at the executable file. As you can see the file is digitally signed by <a href=\"http:\/\/www.freefixer.com\/library\/publisher\/Free%20Sky%20Business%20LP\/\">Free Sky Business LP<\/a>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/exe-free-sky-business-lp.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8356\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/exe-free-sky-business-lp.png\" alt=\"exe-free-sky-business-lp\" width=\"684\" height=\"429\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/exe-free-sky-business-lp.png 684w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/exe-free-sky-business-lp-300x188.png 300w\" sizes=\"(max-width: 684px) 100vw, 684px\" \/><\/a><\/p>\n<p>Typically, when you double-click on a file like this, Windows pops up an User Account Control dialog asking if you trust &#8220;Free Sky Business LP&#8221;. However, this one manage to pop-up and UAC for <strong>Microsoft&#8217;s WMI Commandline Utility<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/WMI-Commandline-Utility-pop-up.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8358\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/WMI-Commandline-Utility-pop-up.png\" alt=\"wmi-commandline-utility-pop-up\" width=\"500\" height=\"282\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/WMI-Commandline-Utility-pop-up.png 500w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/WMI-Commandline-Utility-pop-up-300x169.png 300w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p>If you click no, the UAC dialog will pop-up again and again and again&#8230;<\/p>\n<p>Until you click Yes, which starts the installation of <a href=\"http:\/\/www.freefixer.com\/library\/file\/FileFinder.exe-255156\/\">FileFinder.exe<\/a>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/FileFinder.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-8359\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/FileFinder.png\" alt=\"filefinder\" width=\"922\" height=\"513\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/FileFinder.png 922w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/FileFinder-300x167.png 300w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2016\/12\/FileFinder-768x427.png 768w\" sizes=\"(max-width: 922px) 100vw, 922px\" \/><\/a><\/p>\n<p>So watch out! Don&#8217;t click Yes if the\u00a0<strong>Microsoft&#8217;s WMI Commandline Utility<\/strong> UAC dialog pops up.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was helping out a FreeFixer user this morning, trying to track down some malware in his FreeFixer log that he sent me. While searching for information about a .DLL file, I found a spam post on\u00a0imgur.com, which linked to another web page that started a download of an executable file. And this one is &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/wmi-commandline-utility-malware-pop-up\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">WMI Commandline Utility Malware Pop Ups &#8211; Click NO!<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[19],"tags":[],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8355"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=8355"}],"version-history":[{"count":2,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8355\/revisions"}],"predecessor-version":[{"id":8361,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/8355\/revisions\/8361"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=8355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=8355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=8355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}