New ransomware prevents Windows from starting

Status
Not open for further replies.

davids

New Member
Thread author
Dec 29, 2011
36
0
7
41
A new ransomware variant prevents infected computers from loading Windows by replacing their master boot record (MBR) and displays a message asking users for money, according to security researchers from Trend Micro.

"Based on our analysis, this malware copies the original MBR and overwrites it with its own malicious code," said Cris Pantanilla, a threat response engineer at Trend Micro, in a blog post on Thursday. "Right after performing this routine, it automatically restarts the system for the infection take effect."

The MBR is a piece of code that resides in the first sectors of the hard drive and starts the boot loader. The boot loader then loads the OS.

Instead of starting the Windows boot loader, the rogue MBR installed by the new ransomware displays a message that asks users to deposit a sum of money into a particular account via an online payment service called QIWI, in order to receive an unlock code for their computers.

Read more at http://www.wincert.net/news/security/2916-new-ransomware-prevents-windows-from-starting
 
Infected MBR as one to be a nasty since its a essential component for the OS bootup and some tools may result for unsuccessful removal process.
 
Infected MBR is the worst infection as you can't access the OS to remove it, and it can also stop backup programs (Rollback Rx) from restoring it to a normal state. The only thing from this point is to use a bootable disk to fix the MBR, and it's even more annoying if you have a dual-boot.
 
McLovin said:
In this situation the only way to fix it is to restore a backup and or completely reinstall Windows.

Absolutely. most backup sotwares' boot disk include a WinPE or Linux environment and propose you to make a backup of the MBR
 
So all Window versions and flavours have no protection against the hijacking of the MBR?
 
Not sure for Windows 8 since they focus for security like "secure boot" design to prevent rootkits for startup.
 
Status
Not open for further replies.

You may also like...