Muster e

Started by Glenn, Feb 03, 2010, 08:18:45

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Glenn

Security researchers have spied malware that stashes a copy of itself in a Windows help file to ensure victim computers remain infected.

The trojan, dubbed Muster.e by anti-virus provider McAfee, infects a Windows file called imepaden.hlp so it stores the main components of the malware in encrypted form. In the event the installed malware is removed, the secret payload is decrypted into an executable file called upgraderUI.exe and run by a companion installation file that automatically runs as a Windows service.

"This is hiding in plain site," said Craig Schmugar, a threat researcher at McAfee Labs. "The help file trick is pretty new to us. Usually on the client, we don't see this very often."

The technique ensures Muster.e remains installed on an infected PC even if most of the files associated with the malware are removed. No doubt it's also perplexed its share of users who for the life of them can't figure out how their PCs keep getting reinfected.
http://www.theregister.co.uk/2010/02/03/help_file_trojan/
Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

kinmel

That's scary Glenn, thanks for the heads up   :thumb:
Alan  ‹(•¿•)›

What is the date of the referendum for England to become an independent country ?

Ray

Thanks, Glenn,  :thumb:
Ray
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

It really is getting harder to protect ourselves, isn't it. :( Thanks for the headsup, Glenn.  :thumb:
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Simon

Worrying.  Thanks, Glenn.
Simon.
--
This post reflects my own views, opinions and experience, not those of IDNet.