Free Republic
Browse · Search
General/Chat
Topics · Post Article


1 posted on 06/27/2011 10:21:31 PM PDT by Gomez
[ Post Reply | Private Reply | View Replies ]


To: ShadowAce

ping


2 posted on 06/27/2011 10:22:35 PM PDT by Gomez (shibboleet)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

I may have had this. A google search on popureb shows an MS site which says it “displays advertisments”. That was my problem, plus of course I couldn’t get rid of it. After various consultations, I installed Norton Antivirus from a purchased CDROM, which seemed to get rid of it. I’ve been running for some time now without being bothered. The Norton software impressed me as some serious s**t. It didn’t just do a sweep, but asked if you still had a problem and escalated. It even had explicitly designated anti-Rootkit software, which I invoked. Well, who knows, but as I say, it certainly seems to have worked.


5 posted on 06/27/2011 10:34:54 PM PDT by dr_lew
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

From the comments.. You do not need to reformat.

This article needs to be corrected. The source does NOT say you have to reinstall Windows. Here is how to recover from it. This will not force you to reinstall Windows.

“If your system does get infected with Trojan:Win32/Popureb.E, we advise you to fix the MBR and then use a recovery CD to restore your system to a pre-infected state (as sometimes restoring a system may not restore the MBR). To fix the MBR, we advise that you use the System Recovery Console, which supports a command called “fixmbr”.”


6 posted on 06/27/2011 10:34:54 PM PDT by cableguymn
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez
A recovery CD includes a lot of tools, include ‘fixmbr’ and the ability to restore an earlier system state, not just re-install Windows. Not the first time, nor the last, that Computerworld has taken liberties with the truth..
7 posted on 06/27/2011 10:36:46 PM PDT by kingu (Everything starts with slashing the size and scope of the federal government.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

>At the time, Microsoft’s advice was similar to what Feng is now offering for Popureb.

“If customers cannot confirm removal of the Alureon rootkit using their chosen anti-virus/anti-malware software, the most secure recommendation is for the owner of the system to back up important files and completely restore the system from a cleanly formatted disk,” said Mike Reavey, director of the Microsoft Security Response Center (MSRC), in February 2010.<
*

pFFFT. I solved the Alureon rootkit without re-booting. What do I know. I consulted for Kaspersky and an Avast “Evangelist”. Relying on your anti-virus software alone and Malwarebytes isn’t enough.

I actually witnessed a rootkit take down the Pro version of Malwarebytes. Now that’s scary.


9 posted on 06/27/2011 10:53:04 PM PDT by max americana (FUBO NATION 2012)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

So if this rootkit infection hides from your security programs, how do you know if you are infected?

I use several programs with heuristic scanning that is supposed to prevent any changes and my scans always come up clean.


14 posted on 06/27/2011 11:23:50 PM PDT by wildbill (You're just jealous because the Voices talk only to me.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez
Computer trade magazines are for tech management idiots who couldn't find their asses if they had four robots searching at the top of their legs, and Computerworld is the worst of the worst. Even Dilbert's clueless evil boss wouldn't read Computerworld.

MBR and Recovery do not require reinstallation. Typical overhyped nonsense.

15 posted on 06/27/2011 11:27:06 PM PDT by FredZarguna ("Nothing now is sacred, but infamy.")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez
BS.

Simply use FREE Kapsersky TDS

http://support.kaspersky.com/viruses/solutions?qid=208280684

Step one: stop the virus using rkil. its FREE

http://www.bleepingcomputer.com/download/anti-virus/rkill

You can rename name to other than rkill in case the virus looks for rkill and does not allow its being run. Save it as suzie for example

Step two:The run Kasperksy Root Kill Remover

Step three: Then run MalwareBytes - Costs money but works 100%.

Don't ever pay the scammers for the "Cure", they will take your money and Credit Card data.

No need to ever reinstall your OS.

Maybe you need to do the steps in Safe Mode (f-8) as PC boots , but not always.

18 posted on 06/28/2011 12:37:12 AM PDT by NoLibZone (Be respectful, be courteous , have a plan to kill every flash mob member that threatens you & others)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez
A close friend had what I think may be this virus last week and I ended up re-installing Win XP for him.

While not a "Guru" but after having had a puter for 26 years (starting off with a ol' Kaypro in 85 which required learning DOS and working my way up to and thru all the Windows programs...it got to the point I could repair/reinstall Win 98 in my sleep...) I am not exactly a neophyte, either.

That said, I tried every virus/malware program I knew off (including Spybot, Spyware Doctor, Avast, AVG, Malewarebytes, Adaware, System Mechanic, and maybe a couple of others I can't think of) all to no avail.

That's the 1st time I've not been able to fix a puter that had been infected including the dreaded "About Blank," thus whatever it was, is the worst yet and I keep thinking how I'd like to get my hands on all these bottom-feeding scumbags who develop these programs for whatever pleasure they derive therefrom and even at my advanced age, put (or try anyway?) a whooping on them they would not soon forget.

"There ought to be a law....."

23 posted on 06/28/2011 3:19:29 AM PDT by Conservative Vermont Vet (l)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

26 posted on 06/28/2011 4:47:46 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

27 posted on 06/28/2011 4:48:37 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

You guys are all writing about what program you can install to get rid of a rootkit like this, but when the rootkit completely seizes control of your computer and you cannot even shut it down, use the mouse, etc., you can’t install jack.


31 posted on 06/28/2011 5:57:18 AM PDT by ottbmare (off-the-track Thoroughbred mare)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: NerdDad

Mark


33 posted on 06/28/2011 7:03:59 AM PDT by NerdDad (Aug 7, 1981, I married my soul mate, CDBEAR. 29 years and I'm still teenager-crazy in love with her.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

Bump to find later.


45 posted on 06/28/2011 7:44:42 AM PDT by techcor (I hope Obama succeeds, in being a one term president.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

If you save your data to an external hard drive - then go back to original factory - and reload from the external... will the bad stuff reload with the data?


67 posted on 06/28/2011 10:07:59 AM PDT by GOPJ (1 in 19 collect SS disability- http://www.freerepublic.com/focus/news/2650736/posts?page=131#131)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ShadowAce

If you save your data to an external hard drive - then go back to original factory - and reload from the external... will the bad stuff reload with the data?


68 posted on 06/28/2011 10:08:16 AM PDT by GOPJ (1 in 19 collect SS disability- http://www.freerepublic.com/focus/news/2650736/posts?page=131#131)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Gomez

I’m not worried — I use Linux.


73 posted on 06/28/2011 11:36:41 AM PDT by TexasRepublic (Socialism is the gospel of envy and the religion of thieves)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: decimon; Ernest_at_the_Beach

Thanks Gomez.
A new variant of a Trojan Microsoft calls "Popureb" digs so deeply into the system that the only way to eradicate it is to return Windows to its out-of-the-box configuration, Chun Feng, an engineer with the Microsoft Malware Protection Center (MMPC), said last week on the group's

128 posted on 07/02/2011 7:27:09 AM PDT by SunkenCiv (It's the Obamacare, stupid! -- Thanks Cincinna for this link -- http://www.friendsofitamar.org)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson