This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Non - Profit infected with Torpig

2 min read

This thread's last reply is from June 6, 2011, 7:01 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I work for a non-profit. We are very broke right now. We have been informed by our internet service provider that we have a computer infected with Torpig. I see that you only support home computers. Would you consider helping us? We are an arts organization providing choral and dance instruction to young people aged 3 to 30. We have about 9 computers, the newest of which is a4 years old. Still running Windows XP and Office 2003 - can't afford to upgrade. I have run mawarebytes, stinger, micosoft scanner, and housecall on almost all computers and have not found Torpig. Ran F-Secure on one computer but found nothing. I only I could figure out which computer was infected! If you can't help - can you make some suggestions as to where I might turn.

Thanks
Cathy
Hi doozerfan,
Unfortunately, we cannot help with the situation you have.
First, we only work on Home computers. In addition, the situation you have is not suitable for online remedies.

Torpig (or Mebroot) is an extremely serious infection involving the Master Boot Record of the hard drives.
(This infection can come from the use of P2P programs like utorrent, Limewire, etc. used to download shared "free" music, etc.)

The infected computer becomes part of a "zombie" network under complete control of outside criminals.
Any computer thus infected with this "worm", can spread it to any other machine on the same network.
So, all the machines would have to be removed from the network, and they can only be put back, one at a time, as they are cleaned up.
One mistake about the connection of an infected one, and the whole process would have to start over.

Any of the computers need to be cleaned by a technician AFTER being brought offline.
For this infection, this will usually involve "wiping" the drive, removing the partitions, then re-installing and reformatting the partitions.
Then Windows can be re-installed, updated and supplied with an up to date antivirus.

An example of the recommended process from University of California : http://cnc.ucr.edu/security/announcements/2010_03_04_mebroot.html
For the future, computers used by the public should be operated from Limited type User accounts to restrict the damage from risky Internet behavior.

Sorry we cannot help directly, but hopefully this will give you some idea about the meaning of your situation.

askey127
Thank you for giving me some direction on next steps - much appreciated.