|
-
June 28th, 2011, 07:38 AM
#1
Microsoft: New "Popureb" Rootkit Requires Windows Re-Install
Rootkit infection requires Windows reinstall, says Microsoft
http://www.computerworld.com/s/artic...?taxonomyId=85
-
June 28th, 2011, 08:57 AM
#2
There is a discussion about this over at dslreports. http://www.dslreports.com/forum/r260...says-Microsoft
Several feel the Microsoft approach has contradictions in it and may be an over reaction??
-
June 28th, 2011, 11:09 AM
#3
Looks like a good case for DBAN and doing a clean install alright.
Hope they figure out something better.
-
June 28th, 2011, 11:44 AM
#4
 Originally Posted by HAN
Thanks for the link HAN. Looks interesting.
-
June 28th, 2011, 11:46 AM
#5
 Originally Posted by Train
Looks like a good case for DBAN and doing a clean install alright.
Hope they figure out something better. 
Yep, I hope so too.
--
CMRR - Secure Erase
(Better & faster than DBAN, Killdisk etc.?)
http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml
Read the enclosed .doc and .txt files
Last edited by SpywareDr; June 28th, 2011 at 11:50 AM.
-
June 28th, 2011, 05:45 PM
#6
Naive question
Where from you can get such a nasty ? Is there a way to prevent getting it ?
-
June 28th, 2011, 06:58 PM
#7
 Originally Posted by Ricardo Dávidow
Where from you can get such a nasty ? Is there a way to prevent getting it ?
This nasty is a trojan. To quote McAfee:
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
-
June 28th, 2011, 07:20 PM
#8
-
June 29th, 2011, 12:31 AM
#9
 Originally Posted by SpywareDr
Thanks, that is a new one to me.
-
June 29th, 2011, 05:27 AM
#10
You're welcome.
-
June 29th, 2011, 07:18 AM
#11
Feng provided links to MBR-fixing instructions for XP, Vista and Windows 7
Does that work? Or is a fresh installl the only solution?
If you're happy and you know it......it's your meds.
-
June 29th, 2011, 08:17 AM
#12
If your back up image includes the MBR; why would you need to do a fresh install? Restoring the image would also restore the clean MBR. Am I not understanding something?
-
June 29th, 2011, 09:11 AM
#13
If your back up image includes the MBR; why would you need to do a fresh install? Restoring the image would also restore the clean MBR. Am I not understanding something?
If the imaging program overwrites the MBR with either a clean one, it should work. (Of course, the option to overwrite the infected MBR should be explicit during the restore. Some imaging programs don't make this distinction and if it's not clear that it's being replaced, I don't think the user should make the assumption it has been replaced.)
This is part of the reason I posted the link to the discussion over at dslreports. Several there felt the posting by MS was spreading at least some FUD. And to a degree, I think it is myself...
-
June 29th, 2011, 09:23 AM
#14
 Originally Posted by Steve R Jones
Does that work? Or is a fresh installl the only solution?
Since you are working on the DOS side one would think it would work, but no link(s), and again, how many folks even know what I am talking about?
-
June 29th, 2011, 10:15 AM
#15
 Originally Posted by HAN
If the imaging program overwrites the MBR with either a clean one, it should work. (Of course, the option to overwrite the infected MBR should be explicit during the restore. Some imaging programs don't make this distinction and if it's not clear that it's being replaced, I don't think the user should make the assumption it has been replaced.)
This is part of the reason I posted the link to the discussion over at dslreports. Several there felt the posting by MS was spreading at least some FUD. And to a degree, I think it is myself...
I agree. I like to have the entire drive cloned, which makes things easy if drive failure occurs.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|