Whole Network Most Recent TOP10 Anti-Spam Tools Malware Spam Spam News

 

A Rootkit May Be Lurking on Your Boot Record

Filed in archive Malware by Sue Walsh on January 10, 2008

30445468.jpg
According to Symantec a new rootkit has been found. The kit, named Trojan.Mebroot, lurks in a PC's master book record. What's particularly nasty about this one is it's beginning to infect Windows PCs, and even worse, it's undetectable to most anti-virus software. Symantec says Trojan.Mebroot overwrites the MBR, thereby taking total control of the system:
The main problem is that some versions of Microsoft Windows allow programs to overwrite disk sectors directly (including the MBR) from user mode, without restrictions. As such, writing a new MBR into Sector 0 as a standard user is a relatively easy task. This issue has been known for quite some time, and still affects the 2K/XP families, while Vista was partially secured in 2006 (after Release Candidate 2) after a successful attack demonstration made by Joanna Rutkowska.
It appears to be a derivative of the BootRoot and its kernel has been designed to install a backdoor Trojan. For now, it's only being found on XP systems. Vista's User Account Control seems to be keeping it at bay for now. It takes advantage of the following vulnerabilities:

Microsoft JVM ByteVerify (MS03-011)
Microsoft MDAC (MS06-014) (two versions)
Microsoft Internet Explorer Vector Markup Language (MS06-055)
Microsoft XML CoreServices (MS06-071)

You can check out the history of the rootkit at the Internet Storm Center.


Advertisement


Permalink: A Rootkit May Be Lurking on Your Boot Record
Tags: Server  anti  virus  Email  security  Exchange  anti  virus  Email  security  software  Email  managed  security   

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/110145



Advertisement


Advertisement


CW ToolbarInstall
RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter
Advertisement - Book yours here.

Use our search feature to look for other interesting posts

Just this blog Whole network


Advertisement -
Book yours here..
TierOneAds


 
  • Would you like to have a new interactive marketing channel for your company? Learn more about Sponsored Blogs with Creative Weblogging. See how we helped companies like Weblin and cellity reach their goals.
  • Would you like to reach millions of blog readers every day? See you banner on hundreds of blogs with TierOneAds? Stay in control measuring conversion in real time. Register now.
  • Would you like to make more money blogging? Use TierOneAds a new platform that allows you as a blogger to set your prices per impression. Register now.
  • Do you have a blog with more than 50k page views from the US? Let us market your blog and earn great fix payments and bonuses.
  • Would you like to see your text link here? Let us know!
Advertisement
Book yours here.

TierOneAds


  • Other blogs in the same channel in the Creative Weblogging Network

Advertisement -
Book yours here..
TierOneAds






Advertisement - Book yours here..
 
Tagcloud: Announcements Anti-Spam Tools Archival Tools Events Fight! Malware Phishing Security measures Spam Spam News Sponsored Post Spyware