Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Warning on stealthy Windows virus
BBC News ^ | 11 January 2008

Posted on 01/11/2008 9:40:46 AM PST by Aristotelian

Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts. In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe.

Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code.

Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.

Old tricks

The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR).

This is where a computer looks when it is switched on for information about the operating system it will be running.

"If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog.

Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer.

Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information.

Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.

The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.

(Excerpt) Read more at news.bbc.co.uk ...


TOPICS: Crime/Corruption; Miscellaneous; Russia
KEYWORDS: malware; mebroot; windows
Heads Up!
1 posted on 01/11/2008 9:40:46 AM PST by Aristotelian
[ Post Reply | Private Reply | View Replies]

To: ShadowAce; SunkenCiv

rootkit


2 posted on 01/11/2008 9:47:45 AM PST by george76 (Ward Churchill : Fake Indian, Fake Scholarship, and Fake Art)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Aristotelian

If it can’t be removed while the computer is running, how the heck is it removed?


3 posted on 01/11/2008 9:48:06 AM PST by Red_Devil 232 (VietVet - USMC All Ready On The Right? All Ready On The Left? All Ready On The Firing Line!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

ping


4 posted on 01/11/2008 9:50:38 AM PST by JoJo Gunn (Help control the Leftist population. Have them spayed or neutered. ©)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red_Devil 232
If it can’t be removed while the computer is running, how the heck is it removed?

One way is to remove the hard drive, and install it as the non-boot drive in another computer.

You might also have a bootable CD that can tend to it.
5 posted on 01/11/2008 9:51:25 AM PST by Dr. Sivana (Not a newbie, I just wanted a new screen name.)
[ Post Reply | Private Reply | To 3 | View Replies]

Comment #6 Removed by Moderator

To: Dr. Sivana

So my McAffee won’t be able to detect/delete it? Dang.


7 posted on 01/11/2008 9:57:13 AM PST by scan59 (Let consumers dictate market policies. Government just gets in the way.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Dr. Sivana

So my McAffee won’t be able to detect/delete it? Dang.


8 posted on 01/11/2008 9:57:14 AM PST by scan59 (Let consumers dictate market policies. Government just gets in the way.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: scan59

See, I’m already infected. Causing double posts!


9 posted on 01/11/2008 9:58:00 AM PST by scan59 (Let consumers dictate market policies. Government just gets in the way.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Red_Devil 232

THE ANSWER...

http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-010718-3448-99&tabid=3


10 posted on 01/11/2008 9:58:06 AM PST by stlnative
[ Post Reply | Private Reply | To 3 | View Replies]

To: LibreOuMort

Ping!


11 posted on 01/11/2008 9:58:18 AM PST by sionnsar (trad-anglican.faithweb.com |Iran Azadi| 5yst3m 0wn3d - it's N0t Y0ur5 (SONY) | UN: Useless Nations)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bshomoic

You might also have to format /mbr.


12 posted on 01/11/2008 9:59:18 AM PST by liege
[ Post Reply | Private Reply | To 6 | View Replies]

To: Aristotelian

Hmmm. We use symantec, in fact it just finished its daily scan on this machine a few minutes ago.

That said, I don’t do online banking for the reasons found in this article.


13 posted on 01/11/2008 9:59:31 AM PST by Badeye (No thanks, Huck, I'm not whitewashing the fence for you this election cycle)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Aristotelian; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

14 posted on 01/11/2008 10:02:45 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red_Devil 232

Read the full article...
http://news.bbc.co.uk/2/hi/technology/7183008.stm

~SNIP~ Independent security firm GMER has produced a utility that will scan and remove the stealthy program ~SNIP~

GMER HERE...

http://www.gmer.net/index.php


15 posted on 01/11/2008 10:03:47 AM PST by stlnative
[ Post Reply | Private Reply | To 3 | View Replies]

To: bshomoic

It’s really bad form to suggest destructive commands.

I hope most people will know what that does. Unfortunately, it probably won’t really clean off the rootkit.


16 posted on 01/11/2008 10:04:59 AM PST by MediaMole
[ Post Reply | Private Reply | To 6 | View Replies]

To: Aristotelian

Free tools such http://killbox.net/ and http://www.snapfiles.com/get/removereboot.html will delete files upon reboot.


17 posted on 01/11/2008 10:12:48 AM PST by Manfred the Wonder Dawg (Test ALL things, hold to that which is True.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: george76

No, I’m going to allow it to go gray naturally.


18 posted on 01/11/2008 10:13:58 AM PST by SunkenCiv (https://secure.freerepublic.com/donate/____________________Profile updated Sunday, December 30, 2007)
[ Post Reply | Private Reply | To 2 | View Replies]

The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.
Thank goodness Putin cracked down on all those corrupt oil company and media tycoons. Hate to think of the crime wave that could have happened. I mean, yeah, he's a rough guy, but it's not as if he sells kalishnikov factories and advanced fighters to Venezuela.
19 posted on 01/11/2008 10:16:41 AM PST by SunkenCiv (https://secure.freerepublic.com/donate/____________________Profile updated Sunday, December 30, 2007)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Aristotelian
Wild Level: Low Number of Infections: 0 - 49 Number of Sites: 0 - 2 Geographical Distribution: Low Threat Containment: Moderate Removal: Easy DamageDamage Level: Low...... - This is from the Norton / Symantec website re Mebroot. Seems to contradict this story.
20 posted on 01/11/2008 10:23:05 AM PST by bobsatwork
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red_Devil 232

You would have to boot from a CD and then clear out the mbr..


21 posted on 01/11/2008 10:30:33 AM PST by N3WBI3 (Ah, arrogance and stupidity all in the same package. How efficient of you. -- Londo Mollari)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Aristotelian

Europeans seem to get more viruses because they are also the same people less likely to have antivirus programs installed. I once saw a statistic that showed most viruses found in Europe and Asia almost ten times as many as North America even though North America has more computers. I don’t remember which antivirus company had the stat.


22 posted on 01/11/2008 10:51:13 AM PST by indianaconservative
[ Post Reply | Private Reply | To 1 | View Replies]

To: liege
You might also have to format /mbr.

I think you meant fdisk /mbr.

23 posted on 01/11/2008 11:07:12 AM PST by TChad
[ Post Reply | Private Reply | To 12 | View Replies]

To: Aristotelian

Does anyone know if AVG Free Edition Antivirus will find this?


24 posted on 01/11/2008 11:08:10 AM PST by webschooner
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChad
I think you meant fdisk /mbr.

You're right.

25 posted on 01/11/2008 11:54:49 AM PST by liege
[ Post Reply | Private Reply | To 23 | View Replies]

To: Aristotelian

AVAST.COM


26 posted on 01/11/2008 12:10:49 PM PST by wolfcreek (The Status Quo Sucks!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: stlnative

How do I know this GMER is safe? (no offense to you) Has it been peer revied or tested, etc?


27 posted on 01/11/2008 12:19:45 PM PST by citizen (Capt. McQueeg: "Have any of you an explanation for the quart of missing strawberries?" [click-clack])
[ Post Reply | Private Reply | To 15 | View Replies]

To: citizen

just google GMER


28 posted on 01/11/2008 5:49:02 PM PST by stlnative
[ Post Reply | Private Reply | To 27 | View Replies]

To: citizen

http://www.pcworld.com/article/id,126117-page,1-c,spyware/article.html


29 posted on 01/11/2008 5:51:47 PM PST by stlnative
[ Post Reply | Private Reply | To 27 | View Replies]

To: liege

Instead of getting screwed the first time, how about installing a SW firewall and a hardware firewall? I crawled around the floor with 5 U-320 HDs and that will not happen again. 14 fans and everything in there is happy now. The problem with SCSI is assigning IDs to everything. After that, everything work well at 15k RPM.


30 posted on 01/11/2008 7:52:15 PM PST by BobS
[ Post Reply | Private Reply | To 25 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson