Jump to content
xisto Community
Sign in to follow this  
Saint_Michael

New Rootkit Uses Old Trick To Hide Info on Trojan.Mebroot

Recommended Posts

Well it seems Trojans and root kits are making a deadly combination this especially with a technique thats pretty darn old.

The malware, called Trojan.Mebroot by Symantec, installs itself on the first part of the computer's hard drive to be read on startup, then makes changes to the Windows kernel, making it hard for security software to detect it.

Well at least I understand how or where root kits become effective a bit more, but really you think if everyone is aware of it they would have found a way to patch that hole. I guess not since 5000 computers got tagged with this in 1 month since then. Of course to make it even worse this little Trojan goes after the Master Boot Record (MBR) which is a very bad thing if you get this installed, since now your computer is in complete control of your computer.

Again though I don't know if they Trojan makes are smart or dumb or the people who fall for the traps are dumb, but basically in order to get this installed you need to be suckered into a corrupted website, and then the largest attack starts until your computer gets breeched. Meaning that they most be unloading some of the biggest Trojans and viruses that you may not be protected from and get in that way.

As for protection it depends on what Anti-virus software you have but it seems most vendors have something for this so I check at your vendor's website and see what they have for it.

SOURCE

Share this post


Link to post
Share on other sites

well, i didn't know that viruses still went after the master boot record. I always scan any file I download from an untrusty source using virusscan.jotti.org but the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed. Anyhoo, I just hope it doesn't do more damage like downloading more and more viruses from servers around the world. If it does infect the master boot record, the only way is to re-format your computer or use some dodgy program that "restores your master boot record" I just hope that people won't turn to the old tricks used in the old days when we had those 10megabyte hard drives such as the classic (and sometimes funny) "I LUV U" virus and that "You Have Mail -Click here to go to your inbox" one... because some anti-virus programs don't even care about those viruses anymore...

Share this post


Link to post
Share on other sites

... the biggest security threat comes from my parents. I can't believe that my mum clicked "No" when that WinFixer ad popped up, luckily I unplugged the ethernet cable before the download was completed.

I know just how you feel. I have a friend who broke two laptops in one year from viruses and he won't even let me fix them, but he still has no idea why they broke. I check all untrusted files thoroughly with avast, but he'll open anything that even suggests it can be opened. Anyways, hopefully this get's fixed quickly, because i've heard root kits are impossible to get rid of.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×
×
  • Create New...

Important Information

Terms of Use | Privacy Policy | Guidelines | We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.