Mebroot trojan alert

Miscellaneous Forums/General Discussion/Mebroot trojan alert

A new trojan has just been discovered written by Russian hackers. It attempts to harvest bank login details.

http://news.bbc.co.uk/1/hi/technology/7183008.stm

https://www-secure.symantec.com/en/hk/enterprise/security_response/writeup.jsp?docid=2008-010718-3448-99

This is most concerning - I am very rich and use online banking.

Independent security firm GMER has produced a utility that will scan and remove the stealthy program.

I assume they mean these people.
http://www.gmer.net/files.php

However, I need to check the validity of this site as the BBC did not provide the actual link.


EDIT:
The site seems legit - but I see no recent claims regarding the news item - doesn't make sense.

Symantec:
Note: The rootkit cannot be removed while the OS is running, as it must be removed while the rootkit code itself is not running. During our tests, running the "fixmbr" command from within the Windows Recovery Console successfully removed the malicious MBR entry. To help prevent similar attacks in the future, and if your system BIOS includes the Master Boot Record write-protection feature, now is a good time to enable it!


Well, at least it is easy to get rid of.

Sure been a lot of virus-related activity en masse recently...

Nasty bugger that one is also. I'm a bit curious as to how the exploit works though to compromise the PC, another case of abusing security holes in IE6/7 as usual?

Mmm, does this mean that this site was infected? BRL took us down a week ago to fix security problems.

Well on the symantec page it doesn't specifically say IE, it says on the technical details page under recommendations that it has multiple avenues of attack, browser exploit is mentioned but is only one of its many ways to propagate.

It's known as a blended threat:
http://securityresponse.symantec.com/avcenter/refa.html#blended_threat

I'm still not seeing any evidence from GMER that say they can detect and fix this.

Detecting Mebroot is still not widely available - some AV companies, etc have yet to update to this threat.


Precise Security recommend:
1. Start the computer using Windows Recovery Console:
- Insert the Windows XP CD-ROM into the CD-ROM drive.
- Restart the computer from the CD-ROM drive.
- Press R to start the Recovery Console when the “Welcome to Setup” screen appears.
- Select the installation that you want to access from the Recovery Console.
- Enter the administrator password and press Enter.
- Type “fixmbr” command and press Enter:
(Following the onscreen instructions to restore the Master Boot Record)

2. Exit by typing “Exit” and press enter when done. The computer will now restart automatically.

3. Temporarily Disable System Restore (For WinXP only)
- On the Desktop, Right Click on My Computer
- Select the System Restore Tab
- Mark the “Turn Off System Restore” to disable and UnMark to Enable
- Click Apply on the Bottom of the Dialog Box to save the settings.
- A message “This deletes all existing restore points” will appear, click Yes to disable.
- Click OK.
Note: System Restore must be enabled after cleaning process.

4. Update the virus definitions.

5. Reboot computer in SafeMode
- During BootUp (just before Windows Start) process Press F8 continuously until selection appears
- Use Arrow Up+Down to select SafeMode on the selections menu.

6. Run a full system scan and clean/delete all infected file(s)

The problem is, most people will want to know if they are infected prior to faffing about.

This is stupid - more people are going to become infected because they are Googling info on Mebroot and being drawn into sites that will infect them. This thing has been out there for a few months and we are only just finding out about it.

[AnnoyinglySMUG] Glad i dont use windows for my 'serious' computing. [/AnnoyinglySMUG]

They say it may bypass the firewall. Probably you should use a firewall that even windows doesn't recoginze. Additionally use something like sysinternals process explorer to see what processes are active. This BTW also allows to set several processes in sleep mode, and then kill them all at once. This will prevent typical rootkit behaviour to restart a killed rocess by another viral part of the rootkit.

But basicly I'd say let's get rid off those rootkit coders - I provide the guns. Got to add a smiley here ;)

i emailed AVG about this a while ago to see if AVG would spot it as i use online banking alot for paying wages, tax, vat and such... seems it will

the reply i got

"Thank you for your e-mail.

Yes AVG will protect you from the Mebroot virus, as our software contains a anti-rootkit that will scan your computer for deep rootkits that have been inserted into your system directory.

We have virus definitions for this type of virus, but this kind of virus will re-invent itself and rename itself. But you will still be protected from it.

If you have any other questions or problems then please don't hesitate to contact me.

Kind Regards

Sean
Technical Support Team"

Yea, i got an application called, "reanimator". It install an app to check for rootkits before windows effectively starts up. Quite handy :o)

*edit* get on msn scribbla* :D

Right, I have acquired more info.

Basically, the high risk people (and those who probably were/are/will be affected) are people who do not install Windows updates.

Namely:
Microsoft JVM ByteVerify (MS03-011)
Microsoft MDAC (MS06-014) (two versions)
Microsoft Internet Explorer Vector Markup Language (MS06-055)
Microsoft XML CoreServices (MS06-071)

It has many names with different AV, etc companies - Mebroot is just the name that Symantec have given it.

Symantec = Mebroot
McAfee = StealthMBR
AVG = PSW.Sinowal.C
Kaspersky = backdoor.win32.sinowal.a or Trojan.Win32.Agent.dsj
ESET = Win32/Agent.dsj
TrendMicro = Troj_Sinowal.ad
F-Secure = Trojan:W32/Mebroot.A
Antivir = TR/PSW.Sinowal

I do not feel internet banking to be a safe way to bank. I prefer to walk into a bank and sort it face to face. (or over the phone if you know who you are talking to.)

I had someone get my details off me recently- a worker in a large chain. He took my details and ensured me my account was paid in full. Later recieved a letter saying i hadn't called, called them up and they told me they don't even take payment over the phone! (and that someone then had my details.)

Well, it should be safe. My bank cover me for any losses (regardless of the amount) - I assume most banks have some kind of policy to protect customers.

I'm not worried about the banks, i'm worried about Puki getting my details.

I use online banking as much as possible after several bad experiences with bank tellers. Without online banking so I can check on what people are doing with my money I'd be in a lot of trouble by now.

Heres an example where we put in a couple of checks at the end of the month, went home to pay bills and got a bit of a shock. And notice that both days are quite different, the branch tried to cover their tracks and even wanted me to change accounts.





images don't give the full picture, but at the end of the first day I was overdrawn $13,000 went back to have it fixed. had all funds locked and still couldn't take money out. Next morning they finaly fixed it after I went back again, and then wanted my to close my account and start a new one to hide it.

I've had about 3 other occasions where I have had emergencies and thought it better to go in person. I have to have online banking and use it to keep track of all my bills, checks, credit cards and so I can watch the bank itself.

i found it rather disturbing that iTunes wouldnt fully register without some payment details stored

I only use it to sync my iPod and buy CD's to rip
if i was going to buy i would use pre paid cards
now ive got to keep an extra careful eye out on my account

...

over the phone is a pain
i live in a shared house and have to pray im not over heard when paying for my storage unit oop norf

and once i had to bail my brother out (a lot of money) and he mistyped the number so i go to phone the company concerned (mobile contact at that) it turns out ive called some bloke working for morrisons
if i hadnt spotted some form of confusion this shelf stacker would have had all my details and be semi minted

I totally agree with Evak. Me and my gf came back from hols last year, and she checked her bank online, to find someone had spent £100 odd on online poker. Wouldn't have found that out probably till the bank statement came in at the end of the month...

I use telephone banking to check up on my accounts. I would never use the internet for any kind of banking transaction.
The only thing I use is the credit-card and I always check up on that when ever it's used on line.

I'm also starting to think there is another nastie out there that effects Windows OS's running on a iMac with Boot Camp (I think it's found a home on mine). For some reason Norton Internet Security 2008 will report that there has been a License or subscription problem (NOTE IT'S VALID AND ONLY BEEN INSTALLED ONCE ON THE iMAC AND ACTIVATED) after its been running for a day and can no longer can be activated (I've re-installed it but then the next day it starts again). I've had a Google but found nothing so it looks like I will have to send a email to Symantec support.

heh, I hate phoning the bank, they charge me each time I call. Something like $6, they also charge for going to the desk to withdraw money instead of using the ATM etc.

Personaly I think its really cheeky when they invest our money and then charge us for the priveledge only offering a miniscule 0.3% interest rate on a regular checking account.


Heres an example where we put in a couple of checks at the end of the month, went home to pay bills and got a bit of a shock. And notice that both days are quite different, the branch tried to cover their tracks and even wanted me to change accounts.



I remember when that happened, and it's still shocking they could cock up like that.

I had a bank double charge me recently, only £6, but it cost me £11.20 in bus fair to get it back.

Still, better to assert and let them know you wont be messed with. :-)



heh, I hate phoning the bank, they charge me each time I call. Something like $6, they also charge for going to the desk to withdraw money instead of using the ATM etc.



That's awful! I'm not aware of any banks over here that do that thank god.

My bank currently owe me almost £600 in bank charges from a rough patch last year. I'll be getting it back soon and they havent really complained much. That's not something I can say for my other half's bank, and many others.

Halifax seem pretty secure. I couldnt log in so they locked me out and send two letters about a week apart, one with the username and one with the password, but i decided not to bother due to things like the above little virus, but I suppose if I config my firewall properly we should be alright.

There are a lot of things out there starting to bypass firewalls now- UPNP? you mean, "universal insert-self-into-safe-list-of-firewall?" thats a huge security hole. and why on earch can programs configure the windows firewall? the only way to do that should be through user input. really.

yeah, I do check my windows updates frequently as most things seem to get patched fast, and use NOD32 as a virus checker. So long as you have quite a bit of RAM it stays resident and uses so little CPU you don't really notice it if at all, even with email. And thats on my rather ancient single core CPU.

The bank only charges for phonecalls if you phone a actual branch, not if you call the free helpline. But the 800 like often gives you some muppet to talk to, and you have to wait upwards of 45 minutes on the phone, which is a waste of valuable time, even if you leave it on speaker phone till an actual person starts talking.

Evak - you live in Sacramento? Me too....

hehe, thats cool, Don't know anyone else in indie game dev that does. I'm in East Sacramento(more like Midtown) couple of blocks from McKinley Park.

Cool, I'm in GhettoMichael er, I mean Carmichael