Bootkit Virus
Welcome, Guest. Please login or register. Did you miss your activation email?
Pages: [1]
  Print  
Author Topic: Bootkit Virus  (Read 1181 times)
dannyjks
Sr. Member
****
Posts: 354



View Profile
« on: July 27, 2010, 08:18:51 AM »

has anyone herd of this before
A bootkit is a boot virus that is able to hook and patch Windows to get load into the Windows kernel, and thus getting unrestricted access to the entire computer. It is even able to bypass full volume encryption, because the master boot record (where Stoned is stored) is not encrypted. The master boot record contains the decryption software which asks for a password and decrypts the drive. This is the weak point, the master boot record, which will be used to pwn your whole system
« Last Edit: July 27, 2010, 08:47:59 AM by Britec » Logged

Britec
Administrator
Hero Member
*****
Posts: 3345



View Profile
« Reply #1 on: July 27, 2010, 08:47:42 AM »

You can use MBRCheck to check Master Boot Record

Please Download MBRCheck and save it to your computer.

    * Double click on MBRCheck.exe to run it.
    * When it's done press enter to exit.
    * Then please post the log it produced MBRCheck_(time+date).txt

----------------------------------------------------------------------------------------------
Here is a log of a infected MBR

MBRCheck, version 1.1.1

© 2010, AD



\\.\C: --> \\.\PhysicalDrive0



Size Device Name MBR Status

--------------------------------------------

298 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!


Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

[1] Dump the MBR of a physical disk to file.

[2] Restore the MBR of a physical disk with a standard boot code.

[3] Exit.



Enter your choice:

_____________________________________________________________________
To fix MBR please do the following.

    * Double click on MBRCheck.exe to run it.
    * Type Y then hit enter, to show the options.
    * Type 2 then hit enter, to restore the mbr.
    * When asked for the physical number to fix, type 0 then press enter.
    * When asked to select the mbr to write, type 0 then press enter.
    * Then type yes and press enter to write the new code.


Then reboot your computer, once it's restarted run MBRCheck again as first instructed and post the new log.

Heres The clean log

MBRCheck, version 1.1.1

© 2010, AD


\\.\C: --> \\.\PhysicalDrive0


Size Device Name MBR Status

--------------------------------------------

298 GB \\.\PhysicalDrive0 Windows XP MBR code detected
Logged



dannyjks
Sr. Member
****
Posts: 354



View Profile
« Reply #2 on: July 27, 2010, 08:56:48 AM »

im not infected i just wundered if  you had herd of it before
nevermind  if someone is infected its hear now and they know what to do
thanks
Logged

Britec
Administrator
Hero Member
*****
Posts: 3345



View Profile
« Reply #3 on: July 27, 2010, 09:00:28 AM »

Oh ok dannyjks..I will leave it up here, as you said it will help someone, they still need to run scans first
« Last Edit: July 30, 2010, 02:27:19 PM by Britec » Logged



iisjman07
Jr. Member
**
Posts: 52


View Profile
« Reply #4 on: July 28, 2010, 11:23:18 AM »

Alternatively there's a tool by the same people who make GMER:

http://www.gmer.net/#files

Look for 'MBR Rootkit Detector'
Logged
Britec
Administrator
Hero Member
*****
Posts: 3345



View Profile
« Reply #5 on: July 30, 2010, 02:28:23 PM »

yeah Gmer is a good program, your need to run something like Gmer before anything else really
Logged



Pages: [1]
  Print  
 
Jump to: