Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

September 10th, 2012, 10:50 GMT · By

BLOG

DarkShell Keylogger Comes as Windows Help File

SHARE:

Adjust text size:


Beware of malicious Windows help files Enlarge picture - Beware of malicious Windows help files
To inexperienced users, Windows help files are among the most innocent files around. However, information security enthusiasts know that, in reality, some nasty pieces of malware can hide within a simple .hlp file.

Sophos researchers have come across such a sample. The file is called Amministrazione.hlp (Italian for “administration”) and once it’s executed, it drops a couple of additional elements: Windows Security Center.exe and RECYCLER.DLL.

According to experts, the dynamic library file is actually a keylogger part of the DarkShell Trojan. The malicious element records every keystroke, stores the information in a file, and then sends it back to a remote server.

So there you have it. In case you didn’t know, innocent-looking files that come via unsolicited emails can actually hide a dangerous piece of malware. We advise you to be on the lookout for such schemes and ensure that your antivirus is constantly up to date.

TELL US WHAT YOU THINK:

1,617 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Acquires Malware-Scanning Site VirusTotal

Master of 72,000-Strong Botnet Sentenced to 30 Months in Prison

Cleverly Designed UPS Emails Carry Kuluoz Trojan

Android Malware Owners Fined by UK Regulatory Body

US-CERT Warns of Ransomware Impersonating the FBI

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM