Welcome to the Australian Ford Forums forum.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and inserts advertising. By joining our free community you will have access to post topics, communicate privately with other members, respond to polls, upload content and access many other special features without post based advertising banners. Registration is simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Please Note: All new registrations go through a manual approval queue to keep spammers out. This is checked twice each day so there will be a delay before your registration is activated.

Go Back   Australian Ford Forums > General Topics > Non Ford Related Community Forums > The Bar

The Bar For non Automotive Related Chat

Reply
 
Thread Tools Display Modes
Old 15-01-2008, 06:25 PM   #1
csv8
FF.Com.Au Hardcore
 
csv8's Avatar
 
Join Date: Dec 2004
Location: Central Q..10kms west of Rocky...
Posts: 8,310
Angry Sneaky New Windows Virus Steals Financial Data

Sneaky New Windows Virus Steals Financial DataPosted Jan 14th 2008 11:37AM by Terrence O'Brien
Filed under: Computers



Warning -- a new virus is making its way around the Internet. The virus, dubbed Mebroot, lodges it self in the Master Boot Record (MBR), a part of the hard drive responsible for loading the operating system, where it is out of the reach of most anti-virus software.

The virus itself doesn't actually harm a PC, but it does load other software on the computer, including key-loggers that are triggered when a user visits any of 900 financial institutions' Web sites. The virus then captures the user's log-on information and sends it back to the virus writers, who specialize in stealing confidential information.

The virus is classified as a root kit, meaning it hijacks the administrator functions on the computer and evades detection by normal scanning methods, in this case by hiding in the MBR. Few anti-virus programs can detect the virus, and none can remove it. Because of its location in the MBR, the virus cannot be removed once the computer has been booted.

That said, an independent company GMER has developed software that can scan for and remove the rootkit.

__________________
CSGhia
csv8 is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 06:57 PM   #2
EASYBOSS
Matakana NZ
Donating Member3
 
EASYBOSS's Avatar
 
Join Date: Aug 2005
Location: Matakana NZ
Posts: 3,672
Default

Quote:
Originally Posted by csv8
Sneaky New Windows Virus Steals Financial DataPosted Jan 14th 2008 11:37AM by Terrence O'Brien
Filed under: Computers



Warning -- a new virus is making its way around the Internet. The virus, dubbed Mebroot, lodges it self in the Master Boot Record (MBR), a part of the hard drive responsible for loading the operating system, where it is out of the reach of most anti-virus software.

The virus itself doesn't actually harm a PC, but it does load other software on the computer, including key-loggers that are triggered when a user visits any of 900 financial institutions' Web sites. The virus then captures the user's log-on information and sends it back to the virus writers, who specialize in stealing confidential information.

The virus is classified as a root kit, meaning it hijacks the administrator functions on the computer and evades detection by normal scanning methods, in this case by hiding in the MBR. Few anti-virus programs can detect the virus, and none can remove it. Because of its location in the MBR, the virus cannot be removed once the computer has been booted.

That said, an independent company GMER has developed software that can scan for and remove the rootkit.
Hmmmmmmmmmm sounds sus do you work for GMER? surley other anti-virus software will/can catch this. Are you realy sure in what you are saying
__________________
SOLD : BA XR8 4 Speed Auto in Mercury Silver, Bluepower CIA, Full Diffilipo Big Boy Quad System, Tune, 4.11 Diff Gears, FPV Starter Button, FPV GT Rear Spoiler, Tripod Gauges, PWR Trans Cooler. 230 RWKW's. Many thanks to Chris at Bluepower Racing Developments

Hers : F6X build #150 in Ego, Stock as a Rock, untill the warranty runs out, including the extended one.

My Work Wagon AU Futura Wagon in Gold.

On the Farm : Ford 6600 Tractor
EASYBOSS is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 07:08 PM   #3
Homer
Poor IT dude
 
Join Date: Jan 2005
Location: WA
Posts: 168
Default

http://www.symantec.com/security_res...217-99&tabid=1
Homer is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 07:10 PM   #4
Daymoe
FF.Com.Au Hardcore
 
Join Date: Oct 2007
Posts: 1,082
Default

Quote:
Threat Assessment
Wild

* Wild Level: Low
* Number of Infections: 0 - 49
* Number of Sites: 0 - 2
* Geographical Distribution: Low
* Threat Containment: Easy
* Removal: Easy

Damage

* Damage Level: Low

Distribution

* Distribution Level: Low

Writeup By: Elia Florio
Coming from Symantec who did a pretty crappy A/V program until recently. So it can't be too hard to detect and remove haha.
Daymoe is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 07:24 PM   #5
fordAU
Regular Member
 
Join Date: Mar 2006
Location: Can Do Land
Posts: 332
Default

There is a comprehensive explantion of rootkits and ways to combat them by Kaspersky labs.
http://www.viruslist.com/en/analysis?pubid=168740859

If concerned I recommend to scan your PC with Kaspersky, this AV is very good, one of the few programs I would recommend.
http://www.kaspersky.com/
fordAU is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 08:50 PM   #6
farah9
Regular Member
 
farah9's Avatar
 
Join Date: Oct 2006
Location: Quakers Hill N.S.W
Posts: 69
Default

Yeah, AVG has a free root kit remover you can download, I'd say it would get rid of it fairly easy.
farah9 is offline   Reply With Quote Multi-Quote with this Post
Old 15-01-2008, 10:45 PM   #7
charles_wif_xf
Purveyor of filth
 
Join Date: Oct 2005
Location: Melbourne
Posts: 2,958
Default

Quote:
Originally Posted by 90sFTW
Coming from Symantec who did a pretty crappy A/V program until recently. So it can't be too hard to detect and remove haha.
Their anti virus program still sucks the big one. If anything, it's worse. I pulled it from the shelves after I installed it on my PC. Slowed it down to a bloody crawl. It really is a pathetic program.
charles_wif_xf is offline   Reply With Quote Multi-Quote with this Post
Old 16-01-2008, 01:07 AM   #8
AusM
AusMotorsport
 
Join Date: Dec 2006
Location: Melbourne
Posts: 581
Default

Good site to compare AV programs:
http://www.av-comparatives.org/
AusM is offline   Reply With Quote Multi-Quote with this Post
Old 16-01-2008, 06:40 AM   #9
the_scotsman
MY21.5 Mustang GT
 
the_scotsman's Avatar
 
Join Date: Dec 2004
Location: Shoalhaven, NSW
Posts: 2,450
Default

Quote:
Originally Posted by charles_wif_xf
Their anti virus program still sucks the big one. If anything, it's worse. I pulled it from the shelves after I installed it on my PC. Slowed it down to a bloody crawl. It really is a pathetic program.
I disagree completetly....I beta test for Symantec...and tested their Norton 2008 A/V and Internet Security Suite....the 2008 versions are the best Norton products I have ever used...they are the least resource hungry Norton Products ever...the security suite shits over even programs like Kaspersky for performance IMO.
__________________
2021 Mustang GT in Rapid Red | XDA-Developers Assistant Admin
the_scotsman is offline   Reply With Quote Multi-Quote with this Post
Old 16-01-2008, 09:07 AM   #10
Fev
FF.Com.Au Hardcore
 
Fev's Avatar
 
Join Date: Feb 2007
Location: Cattai, Sydney
Posts: 7,701
Default

ive got AVG and everyone i know raves about it.. i dont really pay attention to it though
__________________
1992 EBII Fairmont Ghia 4.0l <---Click for the Gallery!
Insta@mooneye_ghia
White on bright red smoothies with thick whitewalls. Cruising around to some rockabilly
Fev is offline   Reply With Quote Multi-Quote with this Post
Reply

Thread Tools
Display Modes

Forum Jump


All times are GMT +11. The time now is 04:18 AM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Other than what is legally copyrighted by the respective owners, this site is copyright www.fordforums.com.au
Positive SSL