Microsoft Now Says OS Reinstall Unnecessary for ' Popureb' Trojan

After previously advising Windows users infected with a new rootkit nicknamed 'Popureb' to completely reinstall the OS, Microsoft yesterday retracted, saying a complete wipe is not necessary.

"If your system is infected with Trojan:Win32/Popureb.E, we advise fixing the MBR using the Windows Recovery Console to return the MBR to a clean state," wrote MMPC engineer Chun Feng in an update to a blog post on TechNet.

The previous advise of completely wiping a system was previously given due to the fact that the Trojan operated by overwriting a system's hard drive master boot record to boar its way into a sector accessed only before a computer's BIOS begins the startup process. This causes the OS and security software to not be able to detect the intruding malware.

Feng advises individuals who have been infected to use the Bootrec.exe tool located in the Windows Recovery Environment to repair their system. A detailed explanation on how to use the tool can be found here.

However, removing the 'Popureb' Trojan in this manner may not be enough. "Once you're infected, the best advice is to [reinstall] Windows and start over, said Joe Stewart, director of malware research for Dell SecureWorks, in an interview with Computerworld.  " ... [MBR rootkits] download any number of other malware. How much of that are you going to catch? This puts the user in a tough position."

Marco Giuliani, a threat research analyst at Webroot, also shares Stewart's advice, but also warns that, due to the nature of the malware, wiping a system will not guarantee its removal. "What is really a nightmare is that the Trojan looks like it has bugs and sometimes it hangs the system during the reboot stage," he wrote in a blog posting.

Giuliani and his team at Webroot are currently finishing up on a tool to safely remove the Trojan and will release it after internal testing is complete.


About the Author

Chris Paoli is the site producer for and


  • Microsoft Starting To Roll Out New Excel Connected Data Types

    Microsoft on Thursday announced some Excel and Power BI enhancements that add "connected data types" on top of the standard strings and numbers options.

  • Windows 10 Users Getting New Process for Finding Optional Driver Updates

    Accessing Windows 10 drivers classified as "optional updates" will be more of a manual seek-and-install type of experience, starting on Nov. 5, 2020, Microsoft explained in a Wednesday announcement.

  • Microsoft Changes Privacy Platform Name to SmartNoise

    Microsoft Research has changed the name of its "differential privacy" platform from "WhiteNoise" to "SmartNoise," according to a Wednesday announcement.

  • Why Restarting a Failed SCVMM Job Might Be a Bad Idea

    Occasionally, restarting a failed System Center Virtual Machine Manager job can leave your virtualization infrastructure in an unknown state. Here's how to avoid that.

comments powered by Disqus