Notices
Non Scooby Related Anything Non-Scooby related

Warning on stealthy Windows virus

Thread Tools
 
Search this Thread
 
Old 12 January 2008, 09:30 AM
  #1  
pimmo2000
Scooby Regular
Thread Starter
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default Warning on stealthy Windows virus

I know this is a PC issue, but a lot of normal PC users dont go in the Computer forum !

BBC NEWS | Technology | Warning on stealthy Windows virus

Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts.

In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe.
Many are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code.
Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.
Old tricks
The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR).
This is where a computer looks when it is switched on for information about the operating system it will be running.
"If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog.
Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer.
Once installed the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information.
Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.
The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.
Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December.
Between 12 December and 7 January, iDefense detected more than 5,000 machines that had been infected with the program.
Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software.
Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running.
Independent security firm GMER has produced a utility that will scan and remove the stealthy program. Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.
Old 12 January 2008, 09:47 AM
  #2  
AndyC_772
Scooby Regular
iTrader: (2)
 
AndyC_772's Avatar
 
Join Date: Mar 2001
Location: Swilling coffee at my lab bench
Posts: 9,096
Likes: 0
Received 0 Likes on 0 Posts
Default

That's not the only nasty piece of work currently doing the rounds. There's a web server hack out there which has affected a number of legitimate web sites - at least one of which might well feature on scooby owners' bookmark lists.

See here for more details.
Old 12 January 2008, 09:54 AM
  #3  
pimmo2000
Scooby Regular
Thread Starter
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

The more we know the safer we are !!

cheers
Old 12 January 2008, 12:03 PM
  #4  
warrenm2
Scooby Regular
 
warrenm2's Avatar
 
Join Date: Aug 2003
Location: Epsom
Posts: 5,832
Likes: 0
Received 0 Likes on 0 Posts
Default

the key here is "that use vulnerabilities in Microsoft's browser". Patch IE or use something different and there is no problem....
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
hardcoreimpreza
Computer & Technology Related
21
11 October 2015 03:40 PM
FuZzBoM
Wheels, Tyres & Brakes
16
04 October 2015 09:49 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM



Quick Reply: Warning on stealthy Windows virus



All times are GMT +1. The time now is 05:28 AM.