MBR rootkit

Chewy509

Wotty wot wot.
Joined
Nov 8, 2006
Messages
3,348
Location
Gold Coast Hinterland, Australia
Yep, there's been a lot of talk about this newish rootkit, and Microsoft's advise on how to clean it.

But going back years when I first started with UNIX systems, the advise for a system that had a rootkit installed or had been hacked was simple. "Wipe the HDDs and do a clean install. Restore user data from backup, and verify setup in line with documentation".

Or as Ellen Ripley put "nuke the entire site from orbit. It’s the only way to be sure".

My personal thought is, yes you may have cleaned the rootkit, but what else has been installed?
 

LiamC

Storage Is My Life
Joined
Feb 7, 2002
Messages
2,016
Location
Canberra
Yep, there's been a lot of talk about this newish rootkit, and Microsoft's advise on how to clean it.

But going back years when I first started with UNIX systems, the advise for a system that had a rootkit installed or had been hacked was simple. "Wipe the HDDs and do a clean install. Restore user data from backup, and verify setup in line with documentation".

Or as Ellen Ripley put "nuke the entire site from orbit. It’s the only way to be sure".

My personal thought is, yes you may have cleaned the rootkit, but what else has been installed?

+1. What else is there to say.
 

jtr1962

Storage? I am Storage!
Joined
Jan 25, 2002
Messages
4,366
Location
Flushing, New York
I'm surprised nobody has found a hardware solution to this, something like putting a jumper on the HDD which disables writing to the boot sector. Once you partition a hard drive, there's no reason for anything to be written to the boot sector unless you're repartitioning it.
 

ddrueding

Fixture
Joined
Feb 4, 2002
Messages
19,723
Location
Horsens, Denmark
IIRC, BIOSes have supported a "Virus MBR Lock" for some time, where it will interrupt any changes to the MBR when enabled. Of course, you have to turn it off to install the OS then remember to turn it back on.
 

MaxBurn

Storage Is My Life
Joined
Jan 20, 2004
Messages
3,245
Location
SC
I guess this would be one benefit from using an advanced format drive to boot from?
 

Howell

Storage? I am Storage!
Joined
Feb 24, 2003
Messages
4,740
Location
Chattanooga, TN
Isn't AV software protection of the boot sector as old or nearly as old as the BIOS protection?
 

LunarMist

I can't believe I'm a Fixture
Joined
Feb 1, 2003
Messages
17,468
Location
USA
That is useless when the virus/malware bypasses the AV software.
 
Top