Stealthy Windows virus that can steal bank login information doing the rounds
January 12th, 2008 - 5:19 pm ICT by admin - Send to a friend:
London, January 12 (ANI): Security experts are urging internet users to be alert against a stealthy Windows virus that can steal login details for online bank accounts.
About 5,000 machines, most of which were from Europe, were found to be infected by the malicious program between 12 December and 7 January.
The experts say that it is via booby-trapped websites which use vulnerabilities in Microsoft’s browser to install the attack code that many people fall victim to this virus.
Since the virus has the ability to bury itself deep inside Windows, it is hard to detect it.
It tries to overwrite part of a computers hard drive called the Master Boot Record (MBR). When a computer is switched on, it scans the same portion for information about the operating system it will be running.
Upon installation, the virus called Mebroot usually downloads other malicious programs like keyloggers to steal confidential information.
“If you can control the MBR, you can control the operating system and therefore the computer it resides on,” the BBC quoted Elia Florio as writing on security company Symantec’s blog.
He pointed out that most of the viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer. They lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.
Mebroot has been written by a Russian virus-writing group, which specialises in stealing bank login information.
Security firm iDefense said that Mebroot was discovered in October, but it was used in a series of attacks in early December.
Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus. Mebroot cannot be removed while a computer is running. (ANI)
Related Stories
- Malicious hardware may soon replace computer viruses as hackers tools - May 1, 2008
- Computer virus in space - NASA astronauts get hit - August 28, 2008
- Girls Aloud now surface as computer virus - May 9, 2008
- Win32/glengary.p virus hitting computers - June 13, 2008
- Now, computer bugs in space! - August 28, 2008
- Microsoft calls on Seinfeld to boost Windows - August 22, 2008
- Now, a tool that unlocks Windows PCs without password - March 4, 2008
- Internet users not up-to-date with security skills: Survey - May 19, 2008
- New computer virus infects key government and consumer websites - July 23, 2008
- Beware the Obama in your inbox - November 8, 2008
- Microsoft unveils Windows 7, a fix for disappointing Vista - October 29, 2008
- Now, a virtual Korset to stop killer computer viruses in their tracks - September 10, 2008
- Forensic computer analysts become real employment in police divisions - June 11, 2008
- Microsoft says Internet Explorer users at risk of hacking - December 17, 2008
- The computer helper: restarting your PC - April 17, 2008
- 7 january
- banking systems
- confidential information
- doing the rounds
- financial institutions
- florio
- keyloggers
- login details
- malicious program
- malicious programs
- master boot record
- mbr
- online bank accounts
- russian virus
- security company
- security experts
- security firm
- virus writing
- windows virus
- writing group
Posted in Health Science, |

