How To Stop The Sneaky Propagation Of The Insidious Viruses Mebroot And Torpig
Go to: Previous Article Next Article
Botnets are becoming more prevalent as malware technologies becomes more complex. One of the more destructive examples that hit the scene back in 2008 is known as Mebroot. This virus, which is still around, is a rootkit that changes a computers Master Boot Record permitting it to run prior to the operating system of the computer gets loaded, allowing it to hide itself from anti-virus protection software.
When prioritizing elements of enterprise network security, preventing malware like a rootkit that hides itself and allows for complete control of the computer is of highest priority. Mebroot by itself is rather benign in that it does not have any specific functions but becomes a platform for other harmful software. The most virulent of these is Torpig, a huge botnet.
Torpig has a number of different information stealing pieces of software that analyze the infected computer for credentials, accounts and passwords as well as supposedly granting attackers full control of the computer. In 2009 a team of researchers were able to take control of the Torpig botnet for a period of ten days. During that period, they pulled out over 70GB of stolen data from botnet client machines.
Mebroot gets onto computers by a user accessing a website using a web browser that is older and has not been updated to eliminate the weaknesses that Mebroot uses to install itself on the user's computer. A good way to detect it is with a network based detector, since the virus hides itself on the system on which it is installed which might make it unable to be found.
Only some anti-virus applications can detect and remove Mebroot. If a computer is rebooting or acting infected, yet no virus appears in a scan, fixing the Master Boot Record on the system will remove it if it installed. Searching the web for "Fix MBR" will turn up some different ways to repair the Master Boot Record. After that is done, run a complete virus scan on the machine again to find anything else that was hidden.
The best way to go is to stop machine infestation by keeping browsers patched, and running both host and network based malware detection programs that are continually updated with real time information to stop any infection before it starts.
Article Source: Articlelogy.com
- Credit Cards A big selection of Cards in all flavors: Bad Credit Cards, Secured Cards, Prepaid Cards, Credit Cards for Canada, Low Interest Cards, etc -
Word Count: 387
Reduce Your Debts Without Bankruptcy. See How Much You Can Save. Free Debt Analysis