<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MBR rootkit: VirTool:WinNT/Sinowal.A report</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx</link><description>This week you may have heard or read about a new rootkit that has been reported in the wild that uses the Master Boot Record (MBR) as its Auto-Start Entry Point (ASEP). The malware is being called VirTool:WinNT/Sinowal.A . First we want to let you know</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>RSA Day 4 &amp; 5</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx#3230656</link><pubDate>Sun, 26 Apr 2009 19:37:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3230656</guid><dc:creator>Travis Spencer - Software Engineer</dc:creator><description>&lt;p&gt;On day four and five of my first RSA Conference, I spent most of the day going to lectures about current and future hacks that are being launched against businesses by cyber criminals. I learned a lot, because, as I've...&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3230656" width="1" height="1"&gt;</description></item><item><title>Win32/Sinowal - MBR Rootkit with Password stealer impacts 500,000 accounts</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx#3146472</link><pubDate>Mon, 03 Nov 2008 17:12:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146472</guid><dc:creator>Harry Waldron at myITforum.com</dc:creator><description>&lt;p&gt;Users should ensure their AV protection is up-to-date , as a new variant of this highly stealth rootkit&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3146472" width="1" height="1"&gt;</description></item><item><title>Win32/Sinowal - MBR Rootkit with Password stealer impacts 500,000 accounts</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx#3146470</link><pubDate>Mon, 03 Nov 2008 17:12:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146470</guid><dc:creator>Harry Waldron - Microsoft MVP Blog</dc:creator><description>&lt;p&gt;Users should ensure their AV protection is up-to-date , as a new variant of this highly stealth rootkit&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3146470" width="1" height="1"&gt;</description></item><item><title>Strange things happen when you let people choose their own name, part 2</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx#3140399</link><pubDate>Wed, 22 Oct 2008 18:53:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3140399</guid><dc:creator>The Old New Thing</dc:creator><description>&lt;p&gt;Playing with the free-form-text field.&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3140399" width="1" height="1"&gt;</description></item><item><title>Windows Update Installer &amp;raquo; MBR rootkit: VirTool:WinNT/Sinowal.A report</title><link>http://blogs.technet.com/b/antimalware/archive/2008/01/10/mbr-rootkit-virtool-winnt-sinowal-a-report.aspx#2733952</link><pubDate>Fri, 11 Jan 2008 05:15:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2733952</guid><dc:creator>Windows Update Installer » MBR rootkit: VirTool:WinNT/Sinowal.A report</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://windows-update-installer.blogyblog.info/?p=4076"&gt;http://windows-update-installer.blogyblog.info/?p=4076&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2733952" width="1" height="1"&gt;</description></item></channel></rss>