Where Namibians Meet
User Name: Password: Forgot Password?

 
 Advanced Search
Go Back   The Shebeen > The People's Forums > Internet & Technology


Reply
 
LinkBack Thread Tools
  #1  
Old 14th January 2008, 11:35 AM
inny's Avatar
inny Offline
Junior Member
 
Join Date: Dec 2007
Posts: 16
Blog Entries: 2
Thanks: 34
Thanked 39 Times in 16 Posts
In Agreement: 0
In Agreement With 0 Times in 0 Posts
Credits: 1,519
Exclamation Warning On Stealthy Windows Virus

The creators of the virus are after bank logins and personal data

Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts: In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe. Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code.
Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.

Old tricks: The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR). This is where a computer looks when it is switched on for information about the operating system it will be running. "If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog. Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a gri on a computer. Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information. Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.

The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information. Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December.
Between 12 December and 7 January, iDefense detected more than 5,000 machines that had been infected with the program.

Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software.
Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running. Independent security firm GMER has produced a utility that will scan and remove the stealthy program. Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.
__________________
inny

Last edited by Shebeen; 14th January 2008 at 01:28 PM. Reason: Image with Getty copyright removed
Reply With Quote
The Following User Says Thank You to inny For This Useful Post:
Shebeen (14th January 2008)
  #2  
Old 14th January 2008, 01:27 PM
Shebeen's Avatar
Shebeen Offline
Community Administrator
 
Join Date: Aug 2007
Posts: 1,761
Images: 96
Thanks: 1,648
Thanked 372 Times in 217 Posts
In Agreement: 39
In Agreement With 75 Times in 55 Posts
Credits: 301,888
Default Re: Warning On Stealthy Windows Virus

You can download the GMER utilities here: GMER
Reply With Quote
The Following User Says Thank You to Shebeen For This Useful Post:
inny (14th January 2008)
  #3  
Old 14th January 2008, 01:57 PM
inny's Avatar
inny Offline
Junior Member
 
Join Date: Dec 2007
Posts: 16
Blog Entries: 2
Thanks: 34
Thanked 39 Times in 16 Posts
In Agreement: 0
In Agreement With 0 Times in 0 Posts
Credits: 1,519
Default Re: Warning On Stealthy Windows Virus

Shebeen,
Thank you that was very helpful.
__________________
inny
Reply With Quote
The Following User Says Thank You to inny For This Useful Post:
Shebeen (14th January 2008)
Reply

Bookmarks

Tags
None

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Danger! Warning! ... SCAM!.... Oneword Internet & Technology 2 24th December 2007 07:53 PM
ATM/Card FRaud: Warning from Bank Windhoek Oneword Business & Economics 6 5th December 2007 07:29 PM
Computer virus warning Oneword Internet & Technology 0 1st November 2007 05:28 PM


All times are GMT +2. The time now is 05:58 AM.



Powered by vBulletin® Version 3.7.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
(c) TheShebeen 2008Ad Management by RedTyger


Inactive Reminders By Icora Web Design