<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Removing Popureb Doesn&#8217;t Require a Windows Reinstall</title>
	<atom:link href="http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/</link>
	<description>WEBROOT - INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS</description>
	<lastBuildDate>Fri, 17 May 2013 20:44:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Tammi Wuerz</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-46122</link>
		<dc:creator><![CDATA[Tammi Wuerz]]></dc:creator>
		<pubDate>Wed, 18 Apr 2012 21:59:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-46122</guid>
		<description><![CDATA[Hi your website is outstanding, wish I found it sooner it really really helped me out a lot. Good Job!!!]]></description>
		<content:encoded><![CDATA[<p>Hi your website is outstanding, wish I found it sooner it really really helped me out a lot. Good Job!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Bolton</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14799</link>
		<dc:creator><![CDATA[Chris Bolton]]></dc:creator>
		<pubDate>Wed, 13 Jul 2011 20:01:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14799</guid>
		<description><![CDATA[Hi Marco,

Thanks for this explanation; I understand the concept even though I couldn&#039;t actually do that coding. Regarding the attack vector, it appears to have infected a laptop belonging to my 84 year old mother, who doesn&#039;t tend to use dodgy websites. I guess it can infect any unprotected site. It was on a rolling reboot; I ran fixmbr and reinstalled XP based on where the problem appeared to be and only found out about popureb afterwards - just got to reinstall SP3 and 97 updates now...

Chris]]></description>
		<content:encoded><![CDATA[<p>Hi Marco,</p>
<p>Thanks for this explanation; I understand the concept even though I couldn&#8217;t actually do that coding. Regarding the attack vector, it appears to have infected a laptop belonging to my 84 year old mother, who doesn&#8217;t tend to use dodgy websites. I guess it can infect any unprotected site. It was on a rolling reboot; I ran fixmbr and reinstalled XP based on where the problem appeared to be and only found out about popureb afterwards &#8211; just got to reinstall SP3 and 97 updates now&#8230;</p>
<p>Chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Popureb.E trojan removal tool released for public &#124; Virus prevention and removal security tools</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14720</link>
		<dc:creator><![CDATA[Popureb.E trojan removal tool released for public &#124; Virus prevention and removal security tools]]></dc:creator>
		<pubDate>Mon, 11 Jul 2011 20:39:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14720</guid>
		<description><![CDATA[[...] procedure and saved somewhere on the hard disk. You can read more on details about this trojan here, an article written by the malware researcher Marco Giuliani.The Popureb.E trojan removal tool is [...]]]></description>
		<content:encoded><![CDATA[<p>[...] procedure and saved somewhere on the hard disk. You can read more on details about this trojan here, an article written by the malware researcher Marco Giuliani.The Popureb.E trojan removal tool is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: First Test Post! - A Different Way</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14688</link>
		<dc:creator><![CDATA[First Test Post! - A Different Way]]></dc:creator>
		<pubDate>Mon, 11 Jul 2011 01:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14688</guid>
		<description><![CDATA[[...] researchers with Webroot and CA agreed with Thakur that Popureb could be removed without reinstalling [...]]]></description>
		<content:encoded><![CDATA[<p>[...] researchers with Webroot and CA agreed with Thakur that Popureb could be removed without reinstalling [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Free Anti-Popureb Tool Released &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14636</link>
		<dc:creator><![CDATA[Free Anti-Popureb Tool Released &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Fri, 08 Jul 2011 23:02:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14636</guid>
		<description><![CDATA[[...] week, threat researcher and malware reverse-engineer Marco Giuliani wrote up a fairly technical description of a bootkit &#8212; a rootkit that infects the master boot record of the hard drive, making it very difficult [...]]]></description>
		<content:encoded><![CDATA[<p>[...] week, threat researcher and malware reverse-engineer Marco Giuliani wrote up a fairly technical description of a bootkit &#8212; a rootkit that infects the master boot record of the hard drive, making it very difficult [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beverly Murch</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14528</link>
		<dc:creator><![CDATA[Beverly Murch]]></dc:creator>
		<pubDate>Thu, 07 Jul 2011 21:17:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14528</guid>
		<description><![CDATA[I have your thing making my life miserable - what can I do?]]></description>
		<content:encoded><![CDATA[<p>I have your thing making my life miserable &#8211; what can I do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Giuliani</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14432</link>
		<dc:creator><![CDATA[Marco Giuliani]]></dc:creator>
		<pubDate>Wed, 06 Jul 2011 23:03:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14432</guid>
		<description><![CDATA[Hi Kevin,

I deeply apologize for my late reply to your comment. In this specific case GMER won&#039;t be of any help, at least its MBR rootkit detector. This because the trojan is not hiding at all its code on the MBR, so it doesn&#039;t act as a rootkit and Gmer&#039;s MBR rootkit detector won&#039;t detect anything wrong in the system. 

Systems are being infected by usual well known vectors, that means crack/warez websites, exploited websites containing malicious code, p2p. 

Hope that helps.

Regards,
Marco]]></description>
		<content:encoded><![CDATA[<p>Hi Kevin,</p>
<p>I deeply apologize for my late reply to your comment. In this specific case GMER won&#8217;t be of any help, at least its MBR rootkit detector. This because the trojan is not hiding at all its code on the MBR, so it doesn&#8217;t act as a rootkit and Gmer&#8217;s MBR rootkit detector won&#8217;t detect anything wrong in the system. </p>
<p>Systems are being infected by usual well known vectors, that means crack/warez websites, exploited websites containing malicious code, p2p. </p>
<p>Hope that helps.</p>
<p>Regards,<br />
Marco</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virus Popureb: non è necessario reinstallare Windows</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14078</link>
		<dc:creator><![CDATA[Virus Popureb: non è necessario reinstallare Windows]]></dc:creator>
		<pubDate>Sat, 02 Jul 2011 14:39:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14078</guid>
		<description><![CDATA[[...] via [...]]]></description>
		<content:encoded><![CDATA[<p>[...] via [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Smith</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14033</link>
		<dc:creator><![CDATA[Kevin Smith]]></dc:creator>
		<pubDate>Fri, 01 Jul 2011 13:13:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14033</guid>
		<description><![CDATA[While this is an especially nasty--and sophisticated--bugger we&#039;re all concerned about, it definitely appears to have some different ways to detect and pry it loose.

One tool in particular that appears to be able to ferret it out is GMER, http://www.gmer.net/, a general purpose rootkit detection tool and their MBR rootkit detector.

One thing I&#039;m not seeing anyone discuss is how computers are being infected with this code. It&#039;s definitely happening, yet there&#039;s really been very little mention of what the main attack vectors are.]]></description>
		<content:encoded><![CDATA[<p>While this is an especially nasty&#8211;and sophisticated&#8211;bugger we&#8217;re all concerned about, it definitely appears to have some different ways to detect and pry it loose.</p>
<p>One tool in particular that appears to be able to ferret it out is GMER, <a href="http://www.gmer.net/" rel="nofollow">http://www.gmer.net/</a>, a general purpose rootkit detection tool and their MBR rootkit detector.</p>
<p>One thing I&#8217;m not seeing anyone discuss is how computers are being infected with this code. It&#8217;s definitely happening, yet there&#8217;s really been very little mention of what the main attack vectors are.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft Now Says OS Reinstall Unnecessary for &#8216; Popereb&#8217; Trojan &#8211; JailBake</title>
		<link>http://blog.webroot.com/2011/06/30/removing-popureb-doesnt-require-a-windows-reinstall/#comment-14023</link>
		<dc:creator><![CDATA[Microsoft Now Says OS Reinstall Unnecessary for &#8216; Popereb&#8217; Trojan &#8211; JailBake]]></dc:creator>
		<pubDate>Fri, 01 Jul 2011 02:38:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4628#comment-14023</guid>
		<description><![CDATA[[...] like it has bugs and sometimes it hangs the system during the reboot stage,&#8221; he wrote in a blog posting.Giuliani and his team at Webroot are currently finishing up on a tool to safely remove the Trojan [...]]]></description>
		<content:encoded><![CDATA[<p>[...] like it has bugs and sometimes it hangs the system during the reboot stage,&#8221; he wrote in a blog posting.Giuliani and his team at Webroot are currently finishing up on a tool to safely remove the Trojan [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
