Post new topic    Reply to topic
Login to print this topic
Author Message
Grav!ty
Graham Massey
PostPosted: Wed Jan 09, 2008 10:25 pm Reply with quote

Vice President
Operations
 
 


Joined: 14 Sep 2004
Posts: 20770
Location: Johannesburg
See this news article posted by rippinchikkin Is There A Rootkit Stashed In Your Boot Record?.

Here's a fix:
Quote:
From the recovery console, advised Elia Florio, another Symantec researcher, users can run the "fixmbr" command to remove the rootkit. "To help prevent similar attacks in the future, and if your system BIOS includes the Master Boot Record write-protection feature, now is a good time to enable it," Florio recommended


Source: Computerworld


Not that there are exactly a lot of systems infected at about 5000, but it could be a meanie to get rid of. I guess one would only know if ones system no longer booted. It seems it's "acquired" by visiting certain "host" sites that have been compromised.

I haven't checked right now, but I can't remember that my BIOS has a MBR write protection feature. At least it can be gotten rid of though.
 
Back to top
NT50
Jeff Replogle
PostPosted: Wed Jan 09, 2008 11:19 pm Reply with quote

Vice President
Support
 
 


Joined: 19 Jun 2004
Posts: 9379
Location: Jackson, TN USA
Thank goodness I am running NOD. I am sure they are on top of it also. I do know that NOD monitors the MBR.
 
Back to top
augie
Algis Koscus
PostPosted: Wed Jan 09, 2008 11:35 pm Reply with quote

Management
Community Discussion
 
 


Joined: 25 Aug 2002
Posts: 17566
Location: Laurentians, Quebec
That almost sounds too simplistic of a fix!? confused Checkout Rootkit Revealer from TechNet. I have no idea.
 
Back to top
Back to top
Index >> Security Center >> Is There A Rootkit Stashed In Your Boot Record?

Page 1 of 1

Post new topic   Reply to topic


Tired of the Ads? Registered users have 80% less adverts.