Microsoft is telling Windows users that they'll have to reinstall the operating system if they get infected with a new rootkit that hides in the machine's boot sector.
A new variant of a Trojan Microsoft calls "Popureb" digs so deeply into the system that the only way to eradicate it is to return Windows to its out-of-the-box configuration, Chun Feng, an engineer with the Microsoft Malware Protection Center (MMPC), said last week on the group's blog .
"If your system does get infected with Trojan:Win32/Popureb.E, we advise you to fix the MBR and then use a recovery CD to restore your system to a pre-infected state," said Feng.
A recovery disc returns Windows to its factory settings.
Malware like Popureb overwrites the hard drive's master boot record (MBR), the first sector -- sector 0 -- where code is stored to bootstrap the operating system after the computer's BIOS does its start-up checks. Because it hides on the MBR, the rootkit is effectively invisible to both the operating system and security software.
According to Feng, Popureb detects write operations aimed at the MBR -- operations designed to scrub the MBR or other disk sectors containing attack code -- and then swaps out the write operation with a read operation.
Although the operation will seem to succeed, the new data is not actually written to the disk. In other words, the cleaning process will have failed.
Read More:The driver component protects the data in an unusual way – by hooking the DriverStartIo routine in a hard disk port driver (for example, atapi.sys). The following steps describe the trick:
It calls IoGetDeviceAttachmentBaseRef( ) to retrieve the bottom device object in the disk device stack, that is, the real physical disk device object.
Then it hooks the DriverStartIo routine in the found device’s DRIVER_OBJECT structure
The hooked DriverStartIo routine monitors the disk write operations: If it finds the write operation is trying to overwrite the MBR or the disk sectors containing malicious code, it simply replaces the write operation with a read operation. The operation will still succeed, however, the data will never actually be written onto the disk.
Rootkit Infection Requires Windows Reinstall, Says Microsoft | PCWorld
Last edited:
My Computer
At a glance
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Dell Hell oh Well
- OS
- Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
- CPU
- Intel Core 2 Duo 2.93GHz
- Memory
- Not much with my ADHD
- Graphics Card(s)
- ATI Radeon HD 4350
- Monitor(s) Displays
- 24" HDTV/Monitor
- Screen Resolution
- Blurry after a Scotch or 2
- Hard Drives
- 1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
- Case
- Don't get on my case...man :D
- Cooling
- I have an Air Conditioner & Diet Pepsi
- Keyboard
- Saitek Cyborg
- Mouse
- 10 yr old MS optical mouse that still works
- Internet Speed
- Never fast enough
- Antivirus
- Various
- Browser
- Various
