TweakGuides Forums  

Security & Networking PC Security & Networking/Internet Discussions

 
 
Thread Tools Search this Thread
  #1  
Old 11-20-2008, 05:04 PM
Bobhist's Avatar
Bobhist Bobhist is offline
 
United States

Join Date: Jul 2008
Location: Darlington, S.C.
Posts: 127
Reputation: Bobhist - Invited Member 21
Default Mebroot (Sinowal) Trojan Active Again

Here’s a Trojan that scares the beegees out of me, just discussed by Windows Secrets. I can find no previous mention of it in the Forum by either name.

Quote:
The only company that seems to be in a position to fix the Master Boot Record problem is Microsoft. But it's hard to imagine MS management devoting the time and resources necessary to fix major security holes in a seven-year-old product, particularly when XP's successors (I use the term lightly) don't appear to have the same flaw.

This is short-sighted, however. It's only a matter of time before Sinowal/Mebroot — or an even-more-dangerous offshoot — finds a way to do its damage on Vista systems as well.

If Microsoft decides to take on Sinowal/Mebroot, the company is up against a formidable opponent that draws on many talented programmers. John Hawes at Virus Bulletin says "I recently heard someone estimate that a team of 10 top programmers would need four full months of work to put together the basic setup.
Every member of this forum needs to read it. No further comment on my part is necessary.

http://windowssecrets.com/2008/11/20...ojan/?n=story1
__________________
Everything has its limit--iron ore cannot be educated into gold. (Mark Twain.) (Subject to change by Mr. Twain.)
  #2  
Old 11-20-2008, 07:24 PM
Vittfarne's Avatar
Vittfarne Vittfarne is offline
 
Sweden

Join Date: Aug 2008
Posts: 72
Reputation: Vittfarne - Invited Member 8
Default

I thought this article was really interesting and I will continue to keep an eye on Windowssecret.

Btw, I downloaded the GMER rootscanning program which was recommended in an sidearticle of your article and which was also posted by Big Geek Daddy in this thread:

http://forums.tweakguides.com/showth...highlight=GMER
__________________
| Intel Duo Core 2 E8400 | MO Asus P5E3| 4 GB DDR3 1333 Mhz | Geforce 9800 GTX+ 512 Mb | WD Raptor 74 GB | Creative fatality X-FI Pro | 2 x 320 GB s-ata WD Hdd |
  #3  
Old 11-20-2008, 09:03 PM
Bobhist's Avatar
Bobhist Bobhist is offline
 
United States

Join Date: Jul 2008
Location: Darlington, S.C.
Posts: 127
Reputation: Bobhist - Invited Member 21
Default

@Vittfarne, From the various reports I've read around the Net, GMER is an excellent program. I, too, noted the post by Big Geek Daddy in the past. I use Blacklight Rootkit Eliminator by F-Secure and it works well for me. It's fast and efficient.
__________________
Everything has its limit--iron ore cannot be educated into gold. (Mark Twain.) (Subject to change by Mr. Twain.)
  #4  
Old 11-20-2008, 09:43 PM
spectre's Avatar
spectre spectre is offline
 
Australia

Join Date: Apr 2006
Location: Sydney
Posts: 899
Reputation: spectre - Invited Member 50
Default

It is interesting to note that Vista's UAC seems to play a role here, along with Vista's changes to the MBR.

Quote:
Originally Posted by article
In addition, according to Peter Kleissner, Sinowal/Mebroot — at least in its current incarnation — doesn't infect Vista systems. Windows XP remains its primary target, because Vista's boot method is different and its User Account Control regime gets in the worm's way.
Also, reading through the details I can't help but be horribly "impressed" by the sophistication of the program. Much of it is beyond me but there is a technical description of the program here, which was linked in the article Bobhist linked.
__________________
Forum Rules | Forum Philosophy | Invitation System | For Invited Members

For every complex problem, there is a solution that is simple, neat, and wrong. - H.L. Mencken
  #5  
Old 11-20-2008, 09:55 PM
Bobhist's Avatar
Bobhist Bobhist is offline
 
United States

Join Date: Jul 2008
Location: Darlington, S.C.
Posts: 127
Reputation: Bobhist - Invited Member 21
Default

Spectre, I'm sure you probably know by now that I use XP, and one of the reasons I posted the warning was to alert the Vista guys.

Quote:
This is short-sighted, however. It's only a matter of time before Sinowal/Mebroot — or an even-more-dangerous offshoot — finds a way to do its damage on Vista systems as well.
One of the reasons that it scares the beegees out of me is because we exclusively use online banking. My wife is a retired bank executive, so is well aware of the problems involved, but she assures me that guards are in place in our accounts. I'm not so sure now that I've read this article!
__________________
Everything has its limit--iron ore cannot be educated into gold. (Mark Twain.) (Subject to change by Mr. Twain.)

Last edited by Bobhist : 11-20-2008 at 10:01 PM.
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright © 2010 Koroush Ghazi