- Jul 22, 2014
- 2,525
How do you protect your system from Bootkits, so from Malware that infects BIOS (CMOS/Bios) or MBR? Do you know any software that is able to detect changes and to back up the Bios and MBR? Is Sbabr still a valid program?
i know that good BBs like gdata and a few others can stop rootkits in their tracks and if you get rootkited use drweb boot cd or hitman pro to remove the rootkit and fix any drivers that was change by that rootkit.you can use a sandbox like sandboxie to monitor safely the rootkitHow do you protect your system from Bootkits, so from Malware that infects BIOS (CMOS/Bios) or MBR? Do you know any software that is able to detect changes and to back up the Bios and MBR? Is Sbabr still a valid program?
If a malware "just" infects/encrypts the MBR, is it possible to overwrite it with a clean MBR copy (done with the tools suggested by McBrian) and be sure the MBR is clean again?
That was a good read. Thanks for the link.8 Free Tools to Backup and Restore the Master Boot Record
I use MBRtool on Ultimate Boot CD for DOS to backup MBR to another sector on the same hard disk.
Booting from a clean rescue disk to clean/restore the MBR is an option too, isn't it?
>Flash your BIOS or update it (as updating a BIOS includes to flash it most of the time)
>MBR Rookit -> bootrec /fixboot | bootrec /fixmbr
>BootKit : Use a Live Rescue Environment
Little bit rusty on that too. Been a while since I dealt with these.
if you are infected at this point, using tools will not help much:
in case of Bioskit, flash the BIOS right away, nothing else can be done. Deep format/wipe your drive and reinstall your OS. Faster & safer than using tools that may not clean your machine at 100%.
I then tryed to download gmer from gmer.net; when I download the "exe" I get illogical and different names every time I download it...on VT all O.K apparently, but strange to me...is it really O.K? thks
What can be done to protect the router from changes/attacks?