Home Help Search Login Register
Pages: [1]
  Print  
Author Topic: Bootkit Virus  (Read 94 times)
dannyjks
Full Member
***
Posts: 192


View Profile
« on: July 27, 2010, 08:18:51 AM »

has anyone herd of this before
A bootkit is a boot virus that is able to hook and patch Windows to get load into the Windows kernel, and thus getting unrestricted access to the entire computer. It is even able to bypass full volume encryption, because the master boot record (where Stoned is stored) is not encrypted. The master boot record contains the decryption software which asks for a password and decrypts the drive. This is the weak point, the master boot record, which will be used to pwn your whole system
« Last Edit: July 27, 2010, 08:47:59 AM by Britec » Logged




Britec
Administrator
Hero Member
*****
Posts: 1776



View Profile
« Reply #1 on: July 27, 2010, 08:47:42 AM »

You can use MBRCheck to check Master Boot Record

Please Download MBRCheck and save it to your computer.

    * Double click on MBRCheck.exe to run it.
    * When it's done press enter to exit.
    * Then please post the log it produced MBRCheck_(time+date).txt

----------------------------------------------------------------------------------------------
Here is a log of a infected MBR

MBRCheck, version 1.1.1

© 2010, AD



\\.\C: --> \\.\PhysicalDrive0



Size Device Name MBR Status

--------------------------------------------

298 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!


Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

[1] Dump the MBR of a physical disk to file.

[2] Restore the MBR of a physical disk with a standard boot code.

[3] Exit.



Enter your choice:

_____________________________________________________________________
To fix MBR please do the following.

    * Double click on MBRCheck.exe to run it.
    * Type Y then hit enter, to show the options.
    * Type 2 then hit enter, to restore the mbr.
    * When asked for the physical number to fix, type 0 then press enter.
    * When asked to select the mbr to write, type 0 then press enter.
    * Then type yes and press enter to write the new code.


Then reboot your computer, once it's restarted run MBRCheck again as first instructed and post the new log.

Heres The clean log

MBRCheck, version 1.1.1

© 2010, AD


\\.\C: --> \\.\PhysicalDrive0


Size Device Name MBR Status

--------------------------------------------

298 GB \\.\PhysicalDrive0 Windows XP MBR code detected
Logged




dannyjks
Full Member
***
Posts: 192


View Profile
« Reply #2 on: July 27, 2010, 08:56:48 AM »

im not infected i just wundered if  you had herd of it before
nevermind  if someone is infected its hear now and they know what to do
thanks
Logged




Britec
Administrator
Hero Member
*****
Posts: 1776



View Profile
« Reply #3 on: July 27, 2010, 09:00:28 AM »

Oh ok dannyjks..I will leave it up here, as you said it will help someone, they still need to run scans first
« Last Edit: July 30, 2010, 02:27:19 PM by Britec » Logged




iisjman07
Newbie
*
Posts: 11


View Profile
« Reply #4 on: July 28, 2010, 11:23:18 AM »

Alternatively there's a tool by the same people who make GMER:

http://www.gmer.net/#files

Look for 'MBR Rootkit Detector'
Logged

Britec
Administrator
Hero Member
*****
Posts: 1776



View Profile
« Reply #5 on: July 30, 2010, 02:28:23 PM »

yeah Gmer is a good program, your need to run something like Gmer before anything else really
Logged




Pages: [1]
  Print  
 
Jump to: