New ransomware prevents Windows from starting

Status
Not open for further replies.

davids

New Member
Thread author
Dec 29, 2011
36
A new ransomware variant prevents infected computers from loading Windows by replacing their master boot record (MBR) and displays a message asking users for money, according to security researchers from Trend Micro.

"Based on our analysis, this malware copies the original MBR and overwrites it with its own malicious code," said Cris Pantanilla, a threat response engineer at Trend Micro, in a blog post on Thursday. "Right after performing this routine, it automatically restarts the system for the infection take effect."

The MBR is a piece of code that resides in the first sectors of the hard drive and starts the boot loader. The boot loader then loads the OS.

Instead of starting the Windows boot loader, the rogue MBR installed by the new ransomware displays a message that asks users to deposit a sum of money into a particular account via an online payment service called QIWI, in order to receive an unlock code for their computers.

Read more at http://www.wincert.net/news/security/2916-new-ransomware-prevents-windows-from-starting
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Infected MBR as one to be a nasty since its a essential component for the OS bootup and some tools may result for unsuccessful removal process.
 
V

Vextor

Infected MBR is the worst infection as you can't access the OS to remove it, and it can also stop backup programs (Rollback Rx) from restoring it to a normal state. The only thing from this point is to use a bootable disk to fix the MBR, and it's even more annoying if you have a dual-boot.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
In this situation the only way to fix it is to restore a backup and or completely reinstall Windows.
 
D

Deleted member 178

McLovin said:
In this situation the only way to fix it is to restore a backup and or completely reinstall Windows.

Absolutely. most backup sotwares' boot disk include a WinPE or Linux environment and propose you to make a backup of the MBR
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
So all Window versions and flavours have no protection against the hijacking of the MBR?
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Not sure for Windows 8 since they focus for security like "secure boot" design to prevent rootkits for startup.
 

Gnosis

Level 5
Apr 26, 2011
2,779
This is why I have at least one bootable anti-malware cd at my dispoal at all times; such as, Dr. Web, KBRD, or Avira.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top