Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> New Rootkit Uses Old Trick To Hide, Info on Trojan.Mebroot
Saint_Michael
post Jan 14 2008, 03:01 AM
Post #1


$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3
*********************

Group: [HOSTED]
Posts: 6,305
Joined: 21-September 04
From: 9r33|\| 399$ 4|\|D 5P4/\/\
Member No.: 1,218
T17 GFX Crew



Well it seems Trojans and root kits are making a deadly combination this especially with a technique thats pretty darn old.

QUOTE
The malware, called Trojan.Mebroot by Symantec, installs itself on the first part of the computer's hard drive to be read on startup, then makes changes to the Windows kernel, making it hard for security software to detect it.


Well at least I understand how or where root kits become effective a bit more, but really you think if everyone is aware of it they would have found a way to patch that hole. I guess not since 5000 computers got tagged with this in 1 month since then. Of course to make it even worse this little Trojan goes after the Master Boot Record (MBR) which is a very bad thing if you get this installed, since now your computer is in complete control of your computer.

Again though I don't know if they Trojan makes are smart or dumb or the people who fall for the traps are dumb, but basically in order to get this installed you need to be suckered into a corrupted website, and then the largest attack starts until your computer gets breeched. Meaning that they most be unloading some of the biggest Trojans and viruses that you may not be protected from and get in that way.

As for protection it depends on what Anti-virus software you have but it seems most vendors have something for this so I check at your vendor's website and see what they have for it.

SOURCE
Go to the top of the page
 
+Quote Post
csp4.0
post Jan 14 2008, 10:22 AM
Post #2


NERVE: Interception
*********

Group: [HOSTED]
Posts: 525
Joined: 14-April 07
From: Holy Terra
Member No.: 41,610



well, i didn't know that viruses still went after the master boot record. I always scan any file I download from an untrusty source using virusscan.jotti.org but the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed. Anyhoo, I just hope it doesn't do more damage like downloading more and more viruses from servers around the world. If it does infect the master boot record, the only way is to re-format your computer or use some dodgy program that "restores your master boot record"

I just hope that people won't turn to the old tricks used in the old days when we had those 10megabyte hard drives such as the classic (and sometimes funny) "I LUV U" virus and that "You Have Mail -Click here to go to your inbox" one... because some anti-virus programs don't even care about those viruses anymore...
Go to the top of the page
 
+Quote Post
t3jem
post Jan 14 2008, 10:15 PM
Post #3


Privileged Member
*********

Group: [HOSTED]
Posts: 521
Joined: 9-February 07
Member No.: 38,519



QUOTE(csp4.0 @ Jan 14 2008, 03:22 AM) *
... the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed.


I know just how you feel. I have a friend who broke two laptops in one year from viruses and he won't even let me fix them, but he still has no idea why they broke. I check all untrusted files thoroughly with avast, but he'll open anything that even suggests it can be opened. Anyways, hopefully this get's fixed quickly, because i've heard root kits are impossible to get rid of.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Warning: Virus Spreading Through Msn Messenger(12)
  2. Dangers Of Google Web Accelerator(21)
  3. Get Rid Of Trojan Horse(16)
  4. Big Brother Is Watching .. & Sneaking Your Info(7)
  5. Trojan Emits Bogus Google Adsense Ads(5)
  6. Why Do People Trojan?(14)
  7. Blaster/sasser Worms Info(4)
  8. How Do I Completely Remove Trojan Viruses(32)
  9. Question About Trojan Horse(14)
  10. Trojan /spyware Protection---best---low Resource Util.(5)
  11. Anyone Have Info On "spyhackerz.com"?(17)
  12. Could You Be Infected With Hidden Trojan?(9)
  13. New Twist On An Old Backdoor Trojan(2)
  14. Mcafee Lets Users Download Rootkit Program For Free(2)
  15. New Aim 6.5 Has Trojan- Win32.tibz.ez(1)
  1. Pop-up Virus / Trojan Problem(7)
  2. Bogus Grand Theft Auto Iv Contains Trojan(7)


 



- Lo-Fi Version Time is now: 25th July 2008 - 10:59 AM