Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Report: boot sector viruses and rootkits poised for comeback
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Question about HTML/Framer.Z »
« Security Software Updates 05 April 2008  
AuthorAll Replies

dontsleep

join:2006-08-26
Astoria, NY

reply to Elite
Re: Report: boot sector viruses and rootkits poised for comeback

said by Elite See Profile :

This rootkit is easily defeated though, if you know what you're doing.
Care to elaborate for us?


Elite

join:2002-10-03
Orange, CT
·Optimum Online

Yeah sure.

The current GMER beta, at »www2.gmer.net/beta, can detect and remove all variants of MBRKit at the moment.

Prevx's "Prevx CSI" can at least detect, and I believe remove, all variants of MBRKit.

A number of other antirootkit tools and AVs have varying levels of detection and removal, depending on variants.
--
QUAD!!!!

mysec
Premium
join:2005-11-29


4 edits
said by Elite See Profile :

A number of other antirootkit tools and AVs have varying levels of detection and removal, depending on variants.

Also, easy to prevent from installing:

1) Patching

»www.updatexp.com/mebroot.html
Mebroot has been deliberately installed at websites controlled by the criminals and targets those website visitors who have not patched their computers with the latest security updates from Microsoft.

Mebroot Spreading through High-Traffic, Compromised Web Sites
»msmvps.com/blogs/donna/archive/2···tes.aspx
Today the Italian Web site emule-italia.it had been compromised and was hosting an obfuscated script. The script, when deobfuscated, was showing an iframe pointing to ... which was redirecting users to a server hosting the Neosploit tool. Neosploit is forcing vulnerable PCs to download and install the latest version of the infamous Trojan.Mebroot.


2) White List Protection for Zero-day exploits

Ongoing IFrame attack proving difficult to kill
http://arstechnica.com/news.ars/post/20080318-ongoing-iframe-attack-proving-difficult-to-kill.html
Over the past 12 days, an IFrame injection attack that originally focused on ZDNet Asia has been spreading across the 'Net, changing targets and payloads on an almost daily basis. An iFrame (short for inline frame) is an element of HTML that's used to embed HTML from another source into a webpage.

from 2006



___________________________________________________


___________________________________________________


___________________________________________________

----
rich
Forums » Up and Running » Security » SecurityQuestion about HTML/Framer.Z »
« Security Software Updates 05 April 2008  


Friday, 04-Dec 09:14:19 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [142] Avast Antivirus Has Gone Mad
· [107] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [88] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [69] Sprint Defuses GPS Privacy Media Bomb
· [68] FCC Ponders Moving From PSTN To IP Voice
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Do I have a problem due to AVAST? [Security]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Linux is terrorist - according to MS... [All Things Unix]
· Extjs grid combo box. [Webmasters and Developers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Warrior tank seem underpowered these days [World of Warcraft]