Microsoft: New "Popureb" Rootkit Requires Windows Re-Install
Page 1 of 2 12 LastLast
Results 1 to 15 of 22

Thread: Microsoft: New "Popureb" Rootkit Requires Windows Re-Install

  1. #1
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806

    Angry Microsoft: New "Popureb" Rootkit Requires Windows Re-Install

    Rootkit infection requires Windows reinstall, says Microsoft
    http://www.computerworld.com/s/artic...?taxonomyId=85

  2. #2
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    There is a discussion about this over at dslreports. http://www.dslreports.com/forum/r260...says-Microsoft
    Several feel the Microsoft approach has contradictions in it and may be an over reaction??

  3. #3
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Looks like a good case for DBAN and doing a clean install alright.

    Hope they figure out something better.

  4. #4
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    Quote Originally Posted by HAN View Post
    There is a discussion about this over at dslreports. http://www.dslreports.com/forum/r260...says-Microsoft
    Several feel the Microsoft approach has contradictions in it and may be an over reaction??
    Thanks for the link HAN. Looks interesting.

  5. #5
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806
    Quote Originally Posted by Train View Post
    Looks like a good case for DBAN and doing a clean install alright.

    Hope they figure out something better.
    Yep, I hope so too.

    --

    CMRR - Secure Erase

    (Better & faster than DBAN, Killdisk etc.?)

    http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml

    Read the enclosed .doc and .txt files
    Last edited by SpywareDr; June 28th, 2011 at 11:50 AM.

  6. #6
    Join Date
    May 2001
    Location
    Rosario - Santa Fé - Argentina
    Posts
    599

    Red face Naive question

    Where from you can get such a nasty ? Is there a way to prevent getting it ?

  7. #7
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    Quote Originally Posted by Ricardo Dávidow View Post
    Where from you can get such a nasty ? Is there a way to prevent getting it ?
    This nasty is a trojan. To quote McAfee:
    Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

  8. #8
    Join Date
    May 2001
    Location
    Rosario - Santa Fé - Argentina
    Posts
    599
    Thanks, HAN.

  9. #9
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Quote Originally Posted by SpywareDr View Post

    CMRR - Secure Erase

    (Better & faster than DBAN, Killdisk etc.?)

    http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml

    Read the enclosed .doc and .txt files

    Thanks, that is a new one to me.

  10. #10
    Join Date
    Apr 2005
    Location
    Maryland, USA
    Posts
    17,806

  11. #11
    Join Date
    Sep 1999
    Location
    Clearwater, Fl.
    Posts
    22,610
    Feng provided links to MBR-fixing instructions for XP, Vista and Windows 7
    Does that work? Or is a fresh installl the only solution?
    If you're happy and you know it......it's your meds.

  12. #12
    Join Date
    Aug 2010
    Location
    Southern ON Canada
    Posts
    442
    If your back up image includes the MBR; why would you need to do a fresh install? Restoring the image would also restore the clean MBR. Am I not understanding something?

  13. #13
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    If your back up image includes the MBR; why would you need to do a fresh install? Restoring the image would also restore the clean MBR. Am I not understanding something?
    If the imaging program overwrites the MBR with either a clean one, it should work. (Of course, the option to overwrite the infected MBR should be explicit during the restore. Some imaging programs don't make this distinction and if it's not clear that it's being replaced, I don't think the user should make the assumption it has been replaced.)

    This is part of the reason I posted the link to the discussion over at dslreports. Several there felt the posting by MS was spreading at least some FUD. And to a degree, I think it is myself...

  14. #14
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Quote Originally Posted by Steve R Jones View Post
    Does that work? Or is a fresh installl the only solution?
    Since you are working on the DOS side one would think it would work, but no link(s), and again, how many folks even know what I am talking about?

  15. #15
    Join Date
    Aug 2010
    Location
    Southern ON Canada
    Posts
    442
    Quote Originally Posted by HAN View Post
    If the imaging program overwrites the MBR with either a clean one, it should work. (Of course, the option to overwrite the infected MBR should be explicit during the restore. Some imaging programs don't make this distinction and if it's not clear that it's being replaced, I don't think the user should make the assumption it has been replaced.)

    This is part of the reason I posted the link to the discussion over at dslreports. Several there felt the posting by MS was spreading at least some FUD. And to a degree, I think it is myself...
    I agree. I like to have the entire drive cloned, which makes things easy if drive failure occurs.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •