New Rootkit Uses Old Trick To Hide - Info on Trojan.Mebroot

free web hosting
Open Discussion > CONTRIBUTE > Computers > Computer Security Issues & Exploits

New Rootkit Uses Old Trick To Hide - Info on Trojan.Mebroot

Saint_Michael
Well it seems Trojans and root kits are making a deadly combination this especially with a technique thats pretty darn old.

QUOTE
The malware, called Trojan.Mebroot by Symantec, installs itself on the first part of the computer's hard drive to be read on startup, then makes changes to the Windows kernel, making it hard for security software to detect it.


Well at least I understand how or where root kits become effective a bit more, but really you think if everyone is aware of it they would have found a way to patch that hole. I guess not since 5000 computers got tagged with this in 1 month since then. Of course to make it even worse this little Trojan goes after the Master Boot Record (MBR) which is a very bad thing if you get this installed, since now your computer is in complete control of your computer.

Again though I don't know if they Trojan makes are smart or dumb or the people who fall for the traps are dumb, but basically in order to get this installed you need to be suckered into a corrupted website, and then the largest attack starts until your computer gets breeched. Meaning that they most be unloading some of the biggest Trojans and viruses that you may not be protected from and get in that way.

As for protection it depends on what Anti-virus software you have but it seems most vendors have something for this so I check at your vendor's website and see what they have for it.

SOURCE

 

 

 


Reply

csp4.0
well, i didn't know that viruses still went after the master boot record. I always scan any file I download from an untrusty source using virusscan.jotti.org but the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed. Anyhoo, I just hope it doesn't do more damage like downloading more and more viruses from servers around the world. If it does infect the master boot record, the only way is to re-format your computer or use some dodgy program that "restores your master boot record"

I just hope that people won't turn to the old tricks used in the old days when we had those 10megabyte hard drives such as the classic (and sometimes funny) "I LUV U" virus and that "You Have Mail -Click here to go to your inbox" one... because some anti-virus programs don't even care about those viruses anymore...

Reply

t3jem
QUOTE(csp4.0 @ Jan 14 2008, 03:22 AM) *
... the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed.


I know just how you feel. I have a friend who broke two laptops in one year from viruses and he won't even let me fix them, but he still has no idea why they broke. I check all untrusted files thoroughly with avast, but he'll open anything that even suggests it can be opened. Anyways, hopefully this get's fixed quickly, because i've heard root kits are impossible to get rid of.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.

Recent Queries:-
  1. boot.mebroot - removal tool - 25.49 hr back. (1)
  2. mebroot win32 trojan - 36.77 hr back. (1)
  3. boot mebroot - 39.19 hr back. (1)
  4. new virus that is very similar to the blaster virus? system restart countdown - 68.04 hr back. (2)
  5. boot.mebroot remover - 87.06 hr back. (1)
  6. boot.mebroot remove - 90.93 hr back. (1)
  7. looking for rootkits - 91.02 hr back. (1)
  8. how to remove mebroot.trojan - 94.02 hr back. (1)
  9. mebroot removal - 124.91 hr back. (1)
  10. removing boot.mebroot - 125.33 hr back. (1)
  11. rootkit google - 145.02 hr back. (1)
  12. how to remove mebroot avira - 146.25 hr back. (1)
  13. download mebroot rootkits - 179.75 hr back. (1)
Similar Topics

Keywords : rootkit, trick, hide, info, trojan, mebroot

  1. Antivirus Xp 2008 - Recent Trojan Threat
    find symptoms and fix (10)
  2. Bogus Grand Theft Auto Iv Contains Trojan
    (7)
    Well not really surprise that hackers are targeting this game after scoring $310 million
    dollars in the first day, and what gets me is that people were downloading the pc version days
    before it came out, So either complete stupidity on the fact people though it came out early or the
    fact they didn't know that these games would loaded with malware goodies. Nonetheless, I think
    its time gaming companies start taking cheat codes out of games and write protect files and that way
    they can't be over written. SOURCE ....
  3. Pop-up Virus / Trojan Problem
    Constant pop-up, won't go away (10)
    Hi Guys, Lately I have had this same annoying pop-up dialog box pop up that says: QUOTE NOTICE:
    If your computer has been running slower than normal, it may be infected with Viruses, Adware, or
    Spyware. Adwareremover2007 will perform a quick and completely FREE scan of your system for
    malicious programs. Download AdwareRemover2007 for FREE now! I have scanned it with Avira
    AntiVirus and ad-aware2007. They both returned infected files, which i deleted, but i still have the
    pop-ups. Any ideas?....
  4. New Aim 6.5 Has Trojan- Win32.tibz.ez
    (1)
    I just recently redid me computer and installed a new OS and i went to install AIM ( I HATE AIM BUT
    I KNOW A LOT OF PEOPLE THAT USE IT ) I installed it as normal and my anti-virus went off showing {
    win32.tibz.ez } trojan theres no way i could have got a virus that fast. I installed my OS and
    updated and then installed and update my zonealarm suite. Then i when to install AIM and my
    anti-virus went off and the AIM installer got a error "installation of a component has failed (error
    code: IS-2008 ). But the funny thing is after I get the error I can still use AIM and it ....
  5. Mcafee Lets Users Download Rootkit Program For Free
    (2)
    Since the beginning of 2007 a lot of the security reports I have been reading have mentioning about
    hackers using rootkits to get into people's computers. Google defines a rootkit as a set of
    programs used to hack into a system and gain administrative-level access. Once a program has gained
    access, it can be used to monitor traffic and keystrokes; create a backdoor into the system for the
    hacker's use; alter log files; attack other machines on the network; and alter existing system
    tools to circumvent detection. Rootkits are an extreme form of System Modificatio....
  6. New Twist On An Old Backdoor Trojan
    Suspect this trojan infects or changes BIOS settings (2)
    Seems, there is a variant of backdoor.Sdbot family of worms and IRC backdoor Trojans that is
    disguised as Microsoft Security Adviser. This is quite nasty because it infects system files and is
    very difficult to remove. Trend Micro has a nice online tool called House Call but this trojan
    survived that so you have to look elsewhere to remove it. No telling what the triggers are but I
    simply removed the files and the registry keys pointing to them and now I can't even get into my
    BIOS. Search for msscan.exe if you have it then find RegRun on the net and they claim it r....
  7. Could You Be Infected With Hidden Trojan?
    continuation of DNS hijack (9)
    This post is the continuation of my previous post DNS Hijack SearchAtHand.com Browser Result
    Removal but deserves its own topic. This trojan, not new but something that's been going
    around the web for few years, seems to be quite strong and hard to get rid of. The reason is that it
    randomly changes its full file name when a weak anti-spyware attempts to remove it improperly. I
    have been using Spybot Search & Destroy and Norton Anti-Virus Corporate Edition for many years and
    have never seen such a resilient torjan. Recently I have tried AVG Anti-Spyware but it too....
  8. Anyone Have Info On "spyhackerz.com"?
    failed hacking attempt at my site by these guys (17)
    Hi all I just checked my site, hosted here at trap17.com, and my guestbook was full of html code,
    when i checked the file used to store the content of the guestbook i notice the HTML was as follows
    QUOTE Hacked By Spyhackerz.com www.spyhackerz.com
      src=http://spyhackerz.com/music/index.mp3 width=20 height=15 autostart="true" loop="true">
      So im just wondering if anyone has any info on these people. I recommend not going
    on the website incase they trace your IP etc....I haven't visited yet eithe....
  9. Trojan /spyware Protection---best---low Resource Util.
    PROTECTION LOW RECURSES UTIL . (5)
    My eyes have been completely opened to all this spyware/Trojan junk... /ph34r.gif"
    style="vertical-align:middle" emoid=":ph34r:" border="0" alt="ph34r.gif" /> I'm behind a
    hardware firewall in my Router----running Windows firewall----using the very latest Nortons AV....
    I seem very secure against "viruses" /blink.gif" style="vertical-align:middle" emoid=":blink:"
    border="0" alt="blink.gif" /> But this spyware/trojan thing..... /tongue.gif"
    style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> Oh my! /ohmy.gif"
    style="vertical-a....
  10. Question About Trojan Horse
    how to remove them? (14)
    hi this is the 1st time i am here, so sorry if i posted in the wrong section i received a url thru
    msn messenger, i clicked on it and i got trojan horse on my pc i cant remove it with AVG virus scan
    this is the report: http://i88.photobucket.com/albums/k199/jinwun/viruss.jpg can anyone help me?
    thanks in advance. Welcome to the Trap. I will move it for you. ....
  11. How Do I Completely Remove Trojan Viruses
    anti-virus put them in virus vault (32)
    I have AVG anti-virus on my PC, and a few weeks back it found a trojan virus on my pc. It put it
    into the virus vault but could not heal it. How do I completly remove a trojan virus? Or even can
    I? Do I have to download specific software to remove it, or is there some more complexe way of
    going in to the system?....
  12. Blaster/sasser Worms Info
    (4)
    We all know that when Blaster or Sasser infect your computer the following things are observed: 1.
    The computer gets slow. 2. The search engine Doesnt work. 3. The computer often shuts down if we
    access the internet. Cure: To remove the worm, a removal tool should be downloaded from the
    internet. But it is not possible to do it because as soon as we connect to the internet a countdown
    for system restart starts. This problem can be over come by the following process.. Connect to the
    internet and search for the removal tool. It is also available on microsoft.com When the....
  13. Why Do People Trojan?
    (14)
    It is so retarded how people will send files with trojans attached, lucky for me, my antivirus is a
    king at detecting. But anyways, like 40% of averything i download has a trojan or keylogger, i mean
    come on. Why do you have to steal peoples accounts and know info about people, why cant they get
    there own lives? Just a warning, use caution, people attach trojans to alot of things. Get a good
    antivirus if you like to go on downloading sprees like me =P. I was looking one up online and it
    showed that you can look at the saved internet exploror passwords too. My Norton prot....
  14. Trojan Emits Bogus Google Adsense Ads
    Trojan Emits Bogus Google AdSense Ads (5)
    Trojan Emits Bogus; Google AdSense Ads A Trojan horse program is churning out bogus Google ads
    promoting products Google eschews—gambling, cheap Viagra, girlie photos and adult dating. The
    ads, being targeted at small publishers, are identical to Google AdSense ads except that referral
    graphic buttons are being converted to text, apparently due to a bug in the Trojan, according to the
    publisher who reportedly discovered the Trojan. That publisher, Raoul Bangera, told Techshout.com
    that the non-contextual and risqué content of the ads are what set them apart from....
  15. Big Brother Is Watching .. & Sneaking Your Info
    personal privacy violations (7)
    Hi all, came across this newspaper article (& web posts about it) the other day. Thought it would
    be good for an opinion poll. re: more ways our personal privacy is being invaded. When will it all
    stop ? The article talks about government agencies gaining access to your personal files in an
    underhanded/"sneaky" way without "due process" of law (ie. court orders..etc). Here's the
    link(s) : http://the.honoluluadvertiser.com/article/...ln01a.html-FBI& computer repair shops Guess
    everyone should learn computer encryption & hard drive "wiping" security precautions BE....
  16. Credit Card Info Stolen...
    Security Breach (2)
    hi, The credit card breaches are starting to occur more frequently now.. (at least twice in last
    two months.. as far as I remember). Read the following article: QUOTE In what could be the
    largest data security breach to date, MasterCard International on Friday said information on more
    than 40 million credit cards may have been stolen. Of those exposed accounts, about 13.9 million
    are for MasterCard-branded cards, the company said in a statement. Some 20 million Visa-branded
    cards may have been affected and the remaining accounts were other brands, including Ameri....
  17. Get Rid Of Trojan Horse
    Think I got one.. (16)
    Hi everyone! I think I got the virus Trojan Horse, I have a Norton Anti-virus, and he
    detected the thing!!! He says its in the system32 directory, but he couldn't delete
    it. Does anybody knows how to get rid of this sh*t cause think it lowers my inet speed! and
    comp. performance. Thanks alot! xxx Moved to Security Issues area. Original post did not
    belong in tutorials section. ....
  18. Dangers Of Google Web Accelerator
    Clicking links you don't want to click, and deleting info (21)
    Albeit another topic on Google Web Accelerator has been made, this topic addresses another
    different security concern. This is on the security concern on how Google Web Accelerator operates.
    While your internet connection isn't going any faster, the "illusion" of faster loading pages is
    caused by Google prefeching the pages and links, *before* you visit them. Therefore, all the pages
    have been downloaded into your hard drive. Which brings up the following problem: Since Google Web
    Accl. prefetches ALL links on a page, if the page had a link like: "cancel my accoun....
  19. Warning: Virus Spreading Through Msn Messenger
    any info? (12)
    I was online, and then a friend sent me that file, and I accepted it because he's been wanting
    to send me a program that improves the resolution of the screen. But then my email address was in
    the file name, so I asked him what that was. To my horror, he said 'virus', but it was too
    late, I already opened it and then several chat screens popped-up, and it was auto-sent to some of
    the friends on the contact list. Luckily i was quick enough to ask them not to click on it. And my
    norton internet security and microsoft anti spyware program detected it and asked ....
  20. Trojan Removal
    How to/Best software for removal (11)
    On this topic: http://www.trap17.com/forums/Help-Running-...mize-t8569.html I was told that I
    have a Trojan. I downloaded a program called ScanSpyware and am scanning for Trojans. Is this a
    good program for me to keep, or is there something better?....

    1. Looking for rootkit, trick, hide, info, trojan, mebroot

*RANDOM STUFF*





*SIMILAR VIDEOS*
Searching Video's for rootkit, trick, hide, info, trojan, mebroot

*MORE FROM TRAP17.COM*
advertisement



New Rootkit Uses Old Trick To Hide - Info on Trojan.Mebroot



 

 

 

 

ADD REPLY / Got an Opinion! a humble request :-) RAPID SEARCH! Free Hosting [X]
Express your Opinions, Thoughts or Contribute your information that might help someone here.
Ask your Doubts & Queries to get answers.. "Together, We enlight each other!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE