<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: New Mebroot/Sinowal/MBR/Torpig variant in the wild &#8211; virtually undetected and more dangerous than ever</title>
	<atom:link href="http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/</link>
	<description>malware research, IT Security and life in general :-)</description>
	<lastBuildDate>Wed, 15 Jan 2014 03:13:55 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>By: Elric</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-59</link>
		<dc:creator><![CDATA[Elric]]></dc:creator>
		<pubDate>Wed, 20 Jan 2010 20:32:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-59</guid>
		<description><![CDATA[Does the drive-by infection require admin privileges to work?]]></description>
		<content:encoded><![CDATA[<p>Does the drive-by infection require admin privileges to work?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: STeven</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-58</link>
		<dc:creator><![CDATA[STeven]]></dc:creator>
		<pubDate>Fri, 16 Oct 2009 17:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-58</guid>
		<description><![CDATA[If i get a notice from my ISP i have torpig, how can i find it on a network with over 300 pc]]></description>
		<content:encoded><![CDATA[<p>If i get a notice from my ISP i have torpig, how can i find it on a network with over 300 pc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows reality - The Torpig botnet and LOTS of others out here &#124; keyongtech</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-57</link>
		<dc:creator><![CDATA[Windows reality - The Torpig botnet and LOTS of others out here &#124; keyongtech]]></dc:creator>
		<pubDate>Thu, 07 May 2009 14:06:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-57</guid>
		<description><![CDATA[[...] computers.  I find the name somewhat ironic. Mebroot. MEB root.  Based on this technical analysis:  http://www.trustdefender.com/blog/20...ous-than-ever/  1) Mebroot is mainly deployed through a drive-by download when you visit ]]></description>
		<content:encoded><![CDATA[<p>[...] computers.  I find the name somewhat ironic. Mebroot. MEB root.  Based on this technical analysis:  <a href="http://www.trustdefender.com/blog/20" rel="nofollow">http://www.trustdefender.com/blog/20</a>&#8230;ous-than-ever/  1) Mebroot is mainly deployed through a drive-by download when you visit </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 98 Guy</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-56</link>
		<dc:creator><![CDATA[98 Guy]]></dc:creator>
		<pubDate>Thu, 07 May 2009 12:55:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-56</guid>
		<description><![CDATA[Can someone explain if Mebroot will (or will not) run correctly under Windows 98?  If Mebroot absolutely requires the presence of atapi.sys, svchost.exe or services.exe in order to function, then I can&#039;t see how it can function on a win-98 system.]]></description>
		<content:encoded><![CDATA[<p>Can someone explain if Mebroot will (or will not) run correctly under Windows 98?  If Mebroot absolutely requires the presence of atapi.sys, svchost.exe or services.exe in order to function, then I can&#8217;t see how it can function on a win-98 system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-55</link>
		<dc:creator><![CDATA[Richard]]></dc:creator>
		<pubDate>Mon, 27 Apr 2009 22:04:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-55</guid>
		<description><![CDATA[XP? Did you fixmbr the MBR?

I, too, got a report from my IPs abuse desk. I found all of the symptoms listed above on one of my XP machines (had an unexplained reboot, rg4sfay existed and open by services.exe).

I did the fixmbr routine and the cited signs are gone. But I just got another abuse email from my ISP. I can&#039;t reach a human there to find out why/when this latest warning was triggered.

Approaching max paranoia and running out of ideas how to proceed.]]></description>
		<content:encoded><![CDATA[<p>XP? Did you fixmbr the MBR?</p>
<p>I, too, got a report from my IPs abuse desk. I found all of the symptoms listed above on one of my XP machines (had an unexplained reboot, rg4sfay existed and open by services.exe).</p>
<p>I did the fixmbr routine and the cited signs are gone. But I just got another abuse email from my ISP. I can&#8217;t reach a human there to find out why/when this latest warning was triggered.</p>
<p>Approaching max paranoia and running out of ideas how to proceed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-54</link>
		<dc:creator><![CDATA[Luke]]></dc:creator>
		<pubDate>Tue, 21 Apr 2009 03:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-54</guid>
		<description><![CDATA[And I&#039;ve got infected with a newer version of this virus and so far no tool has been able to detect it! I know it&#039;s there, however, as I got informed by my network administrator that something is sending requests from my machine. I&#039;ve tried everything and all detection tools fail. Any ideas?]]></description>
		<content:encoded><![CDATA[<p>And I&#8217;ve got infected with a newer version of this virus and so far no tool has been able to detect it! I know it&#8217;s there, however, as I got informed by my network administrator that something is sending requests from my machine. I&#8217;ve tried everything and all detection tools fail. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-53</link>
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 20 Apr 2009 11:16:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-53</guid>
		<description><![CDATA[Hi mario, no worries. This blog is for technical information and any info that helps people is very much appreciated. So please do post this kind of info. Your info is very much appreciated. Thanks]]></description>
		<content:encoded><![CDATA[<p>Hi mario, no worries. This blog is for technical information and any info that helps people is very much appreciated. So please do post this kind of info. Your info is very much appreciated. Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mario</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-52</link>
		<dc:creator><![CDATA[mario]]></dc:creator>
		<pubDate>Mon, 20 Apr 2009 06:52:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-52</guid>
		<description><![CDATA[Hi admin, sorry if I mentioned your &quot;competitors&quot; here, but their fix is so easy and effective that I thought could be useful to many like me that have been infected because they do not use (yet) your products. When you see all your passwords and mail stored in a hidden file, well, you are scared and desperate, and any solution, even temporary, is welcome.
Having said that, I have to thank you because 1) your article is very informative and 2) you were the first to point out that the trojan comes through acrobat reader files: just update acrobat reader and you are ok (for now).
I also mentioned your article as a valuable source to many collegues and on other security forums, and I hope this will help you forgive me.
Keep up the good work!]]></description>
		<content:encoded><![CDATA[<p>Hi admin, sorry if I mentioned your &#8220;competitors&#8221; here, but their fix is so easy and effective that I thought could be useful to many like me that have been infected because they do not use (yet) your products. When you see all your passwords and mail stored in a hidden file, well, you are scared and desperate, and any solution, even temporary, is welcome.<br />
Having said that, I have to thank you because 1) your article is very informative and 2) you were the first to point out that the trojan comes through acrobat reader files: just update acrobat reader and you are ok (for now).<br />
I also mentioned your article as a valuable source to many collegues and on other security forums, and I hope this will help you forgive me.<br />
Keep up the good work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-51</link>
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 20 Apr 2009 00:14:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-51</guid>
		<description><![CDATA[Hi mario, you are right. GMER has updated their detection and removal tool on April 15. Many other security vendors did the same and after they analyzed the trojan, they provide now updated protection tools... However just a word of caution: these updated tools will only work up until Mebroot changes again and then they are useless again... So far, TrustDefender has always picked up an infection based on our Forensics Engine :-)]]></description>
		<content:encoded><![CDATA[<p>Hi mario, you are right. GMER has updated their detection and removal tool on April 15. Many other security vendors did the same and after they analyzed the trojan, they provide now updated protection tools&#8230; However just a word of caution: these updated tools will only work up until Mebroot changes again and then they are useless again&#8230; So far, TrustDefender has always picked up an infection based on our Forensics Engine <img src="http://www.tidos-group.com/blog/wp-includes/images/smilies/icon_smile.gif" alt=":-)" class="wp-smiley" /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mario</title>
		<link>http://www.tidos-group.com/blog/2009/04/04/new-mebrootsinowalmbrtorpig-variant-in-the-wild-virtually-undetected-and-more-dangerous-than-ever/#comment-50</link>
		<dc:creator><![CDATA[mario]]></dc:creator>
		<pubDate>Sun, 19 Apr 2009 16:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=125#comment-50</guid>
		<description><![CDATA[This is a nasty one, only Process Explorer from Microsoft shows handles pointing to rg4sfay, ydf8dk. NO TRACES in Task Manager, Msconfig, Services.msc and registry !!!!!!
BUT (good news)
Solution is very easy!!
1) disable system restore (just in case)
2) clean up c:/windows/prefetch (just in case again)
3) go to http://www2.gmer.net/mbr/ , download the .exe at bottom of page and run it 3 times as described FROM SAFE MODE of course.
4) restart and enable system restore.

now you can delete the 2 files and process explorer shows nothing suspicious.
As a bonus, after deleting prefetch my pc starts using 50% time as before!
Found the mbr solution in an Italian forum
http://www.hwupgrade.it/forum/showthread.php?t=1715546
looks like in Italy there are many similar cases.
Cheers
Mario]]></description>
		<content:encoded><![CDATA[<p>This is a nasty one, only Process Explorer from Microsoft shows handles pointing to rg4sfay, ydf8dk. NO TRACES in Task Manager, Msconfig, Services.msc and registry !!!!!!<br />
BUT (good news)<br />
Solution is very easy!!<br />
1) disable system restore (just in case)<br />
2) clean up c:/windows/prefetch (just in case again)<br />
3) go to <a href="http://www2.gmer.net/mbr/" rel="nofollow">http://www2.gmer.net/mbr/</a> , download the .exe at bottom of page and run it 3 times as described FROM SAFE MODE of course.<br />
4) restart and enable system restore.</p>
<p>now you can delete the 2 files and process explorer shows nothing suspicious.<br />
As a bonus, after deleting prefetch my pc starts using 50% time as before!<br />
Found the mbr solution in an Italian forum<br />
<a href="http://www.hwupgrade.it/forum/showthread.php?t=1715546" rel="nofollow">http://www.hwupgrade.it/forum/showthread.php?t=1715546</a><br />
looks like in Italy there are many similar cases.<br />
Cheers<br />
Mario</p>
]]></content:encoded>
	</item>
</channel>
</rss>
