Audio By Carbonatix
Security experts are warning about a stealthy Windows virus that steals login details for online bank accounts.
In the last month, the malicious program has racked up about 5,000 victims - most of whom are in Europe.
The creators of the virus are after bank logins and personal data and are falling victim via booby-trapped websites that use vulnerabilities in Microsoft's browser to install the attack code.
Experts say the virus is dangerous because it buries itself deep inside Windows to avoid detection.
Old tricks
The malicious program is a type of virus known as a rootkit and it tries to overwrite part of a computer's hard drive called the Master Boot Record (MBR): where a computer looks when it is switched on for information about the operating system it will be running.
"If you can control the MBR, you can control the operating system and therefore the computer it resides on," wrote Elia Florio on security company Symantec's blog.
Mr Florio pointed out that many viruses dating from the days before Windows used the Master Boot Record to get a grip on a computer.
Once installed, the virus, dubbed Mebroot by Symantec, usually downloads other malicious programs, such as keyloggers, to do the work of stealing confidential information.
Most of these associated programs lie in wait on a machine until its owner logs in to the online banking systems of one of more than 900 financial institutions.
The Russian virus-writing group behind Mebroot is thought to have created the torpig family of viruses that are known to have been installed on more than 200,000 systems. This group specialises in stealing bank login information.
Security firm iDefense said Mebroot was discovered in October but started to be used in a series of attacks in early December.
Between 12th December and 7th January, iDefense detected more than 5,000 machines that had been infected with the program. Analysis of Mebroot has shown that it uses its hidden position on the MBR as a beachhead so it can re-install these associated programs if they are deleted by anti-virus software.
Although the password-stealing programs that Mebroot installs can be found by security software, few commercial anti-virus packages currently detect its presence. Mebroot cannot be removed while a computer is running.
Independent security firm GMER has produced a utility that will scan and remove the stealthy program.
Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.
SOURCE: BBC
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
UK-based social protection expert Andy Owusu to speak at IAF & TTAG–EGA Summit in Accra on May 8
3 minutes -
Parliament set to reconvene on May 21
9 minutes -
Sammi Awuku inaugurates constituency office and launches Youth Skills Programme in Akuapem North
12 minutes -
OPD shutdown at Korle Bu leaves patients stranded, emergency unit overwhelmed
40 minutes -
ACFIF 2026: Ex-President Kufuor to deliver special address on Africa Cocoa Vision 2050
49 minutes -
4 individuals linked to PDS arrested over suspected ECG funds transfer — Kwakye Ofosu
54 minutes -
BECE: Five arrested over exam malpractice – WAEC
54 minutes -
Kofi Jumah reportedly hospitalised as GH¢55m bail conditions remain unmet
59 minutes -
‘Behind the Lens with Queen Liz’ explores concepts of heaven and jannah
1 hour -
Quality Insurance marks 30 years with push for women-focused innovation, trust-building
1 hour -
Ghana’s Ambassador to Libya commends CEO of Afro Arab Group
1 hour -
Nkwanta crisis: Fresh gunfire sends residents fleeing; 26-year-old rider shot
1 hour -
Two BECE candidates killed in motor crash in Upper West
1 hour -
PSG, Manchester United lead race for FC Nordsjaelland star Prince Amoako Jnr
1 hour -
Lawra MP urges BECE candidates to avoid malpractice, assures support
1 hour