<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mebroot root kit infection (aka Sinowal, aka Torpig)</title>
	<atom:link href="http://cdonner.com/mebroot-root-kit-infection.htm/feed" rel="self" type="application/rss+xml" />
	<link>http://cdonner.com/mebroot-root-kit-infection.htm</link>
	<description>We know accurately only when we know little, with knowledge doubt increases.  (Goethe)</description>
	<lastBuildDate>Mon, 06 Feb 2012 12:46:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Christian Donner</title>
		<link>http://cdonner.com/mebroot-root-kit-infection.htm/comment-page-1#comment-4978</link>
		<dc:creator>Christian Donner</dc:creator>
		<pubDate>Thu, 16 Apr 2009 12:21:28 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=496#comment-4978</guid>
		<description>Mjt, unfortunately I did not run RootKitRevealer prior to running FixMbr. It did not reveal anything afterwards. I ran Combofix, however, for the first time on my machine, and it found and removed a handful files, one or two of which could have been related.</description>
		<content:encoded><![CDATA[<p>Mjt, unfortunately I did not run RootKitRevealer prior to running FixMbr. It did not reveal anything afterwards. I ran Combofix, however, for the first time on my machine, and it found and removed a handful files, one or two of which could have been related.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mjt</title>
		<link>http://cdonner.com/mebroot-root-kit-infection.htm/comment-page-1#comment-4975</link>
		<dc:creator>mjt</dc:creator>
		<pubDate>Thu, 16 Apr 2009 11:23:20 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=496#comment-4975</guid>
		<description>So, would RootkitRevealer have helped/detected
this strain? I&#039;ve seen no mention whether this
has been tried, although I&#039;ve seen references
to GMER. Interesting read:
http://forum.sysinternals.com/forum_posts.asp?TID=18626</description>
		<content:encoded><![CDATA[<p>So, would RootkitRevealer have helped/detected<br />
this strain? I&#8217;ve seen no mention whether this<br />
has been tried, although I&#8217;ve seen references<br />
to GMER. Interesting read:<br />
<a href="http://forum.sysinternals.com/forum_posts.asp?TID=18626" rel="nofollow">http://forum.sysinternals.com/forum_posts.asp?TID=18626</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TrustDefender Labs » New Mebroot Sinowal MBR Torpig variant in the wild - virtually undetected and more dangerous than ever</title>
		<link>http://cdonner.com/mebroot-root-kit-infection.htm/comment-page-1#comment-4436</link>
		<dc:creator>TrustDefender Labs » New Mebroot Sinowal MBR Torpig variant in the wild - virtually undetected and more dangerous than ever</dc:creator>
		<pubDate>Sun, 05 Apr 2009 09:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://cdonner.com/?p=496#comment-4436</guid>
		<description>[...] However now since March 26, 2009 we are seeing a completely new variant with major &#8220;improvements&#8221; or &#8220;enhancements&#8221; and a clear focus on being undetected. It defeats all detection tools and methods in place today - (e.g. GMER has provided a technical analysis with a detection/removal tool here. However it is useless with this new variant). Your current Antivirus Solutions are almost all ineffective as Christian Donner wrote in his blog how he got infected even though he runs an on-access scanner with full scans from 3 different well known AV vendors. His special Linux boot CD with Kaspersky, Avira Antivir and Bitdefender didn&#8217;t detect anything! (http://cdonner.com/mebroot-root-kit-infection.htm) [...]</description>
		<content:encoded><![CDATA[<p>[...] However now since March 26, 2009 we are seeing a completely new variant with major &#8220;improvements&#8221; or &#8220;enhancements&#8221; and a clear focus on being undetected. It defeats all detection tools and methods in place today - (e.g. GMER has provided a technical analysis with a detection/removal tool here. However it is useless with this new variant). Your current Antivirus Solutions are almost all ineffective as Christian Donner wrote in his blog how he got infected even though he runs an on-access scanner with full scans from 3 different well known AV vendors. His special Linux boot CD with Kaspersky, Avira Antivir and Bitdefender didn&#8217;t detect anything! (<a href="http://cdonner.com/mebroot-root-kit-infection.htm" rel="nofollow">http://cdonner.com/mebroot-root-kit-infection.htm</a>) [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

