Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Self-destructing virus kills off PCs
teoti ^ | 9:38 pm 05/05/2015 | tricpe

Posted on 05/07/2015 7:01:36 PM PDT by Utilizer

click here to read article


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-62 next last
No word on how to protect from it or prevent it so far.
1 posted on 05/07/2015 7:01:37 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

Ping.


2 posted on 05/07/2015 7:02:09 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

It’s called Windows?


3 posted on 05/07/2015 7:02:13 PM PDT by nickcarraway
[ Post Reply | Private Reply | To 1 | View Replies]

To: nickcarraway

It’s called Windows?

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

No, It’s called Windows Marketing.


4 posted on 05/07/2015 7:06:06 PM PDT by loungitude (The truth hurts.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

Can it overwrite the MBR on a Safe Boot / UFEI machine?


5 posted on 05/07/2015 7:08:41 PM PDT by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Nasty virus, no fix for it yet ... PING!

You can find all the Windows Ping list threads with FR search: search on keyword "windowspinglist".

Thanks to Utilizer for the ping!

6 posted on 05/07/2015 7:10:35 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: All

More info:

Cisco researchers have identified a new malware sample, called Rombertik, that takes its detection evasion features one step further than the average cyber threat.

Instead of simply self-destructing when analysis tools are detected, Rombertik attempts to destroy the device’s master boot record (MBR), researchers wrote in a blog post.

This malware spreads through spam and phishing messages sent to possible victims.

In one example, attackers attempted to convince a user to download an attached document in an email. If downloaded and unzipped, a file that looks like a document thumbnail comes up. Although it mimics a PDF icon, it is actually a .SCR screensaver executable file containing the malware.

At this point Rombertik will first run anti-analysis checks to determine whether it is running within a sandbox. If it isn’t, it will then decrypt and install itself, which then allows it to launch a second copy of itself and to overwrite the second copy with the malware’s core functionality.

...

http://www.itnews.com.au/News/403620,new-malware-strain-destroys-master-boot-record-to-avoid-detection.aspx


7 posted on 05/07/2015 7:11:02 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: loungitude; nickcarraway
>> It’s called Windows?

> No, It’s called Windows Marketing.

Wow, tough crowd tonight... :-)

8 posted on 05/07/2015 7:12:01 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

DANG!!


9 posted on 05/07/2015 7:13:46 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer
Restoring a PC with its MBR deleted involves reinstalling Windows, which could mean important data is lost.

No, it doesn't.

10 posted on 05/07/2015 7:14:24 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic

No word yet. It has just been detected and the coders are still examining it.

Best to have backups ready now just in case.


11 posted on 05/07/2015 7:15:08 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: tacticalogic

If this happens you take the infected hard drive and install it as a slave (or non bootable) on a clean desktop computer. Pull off all necessary files you want to keep. Wipe clean the infected hard drive and reuse it


12 posted on 05/07/2015 7:16:52 PM PDT by dennisw (The first principle is to find out who you are then you can achieve anything -- Buddhist monk)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Billthedrill; Utilizer
>> Restoring a PC with its MBR deleted involves reinstalling Windows, which could mean important data is lost.

> No, it doesn't.

If all that's overwritten is the MBR itself, that can be reconstructed. Hell even old FDISK/MBR might do it.

But if the partition table got overwritten and it was anything other than trivial, the average user will be outta luck.

13 posted on 05/07/2015 7:19:27 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer

bing


14 posted on 05/07/2015 7:19:35 PM PDT by jetson (Can I catch you a delicious bass...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

No doubt created by liberal democrats so Hillary can say that is what happened to all of her e-mails. Yeah, that’s the ticket, virus destroyed my e-mails, and Morgan Fairchild’s too.


15 posted on 05/07/2015 7:20:21 PM PDT by TonyM
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

MBR wipers are a quarter century old. Restoring a partition table is trivial. This is ridiculous.


16 posted on 05/07/2015 7:20:43 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 13 | View Replies]

To: dennisw
If this happens you take the infected hard drive and install it as a slave (or non bootable) on a clean desktop computer. Pull off all necessary files you want to keep. Wipe clean the infected hard drive and reuse it

Done it many times when doing bare-metal upgrades. The downside is having to re-install all the software.

17 posted on 05/07/2015 7:24:55 PM PDT by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Utilizer
Security expert Graham Cluley said destructive viruses such as Rombertik were quite rare.
So far.
18 posted on 05/07/2015 7:25:09 PM PDT by Bratch
[ Post Reply | Private Reply | To 1 | View Replies]

To: Billthedrill
> MBR wipers are a quarter century old. Restoring a partition table is trivial. This is ridiculous.

I'm not going to argue with you. I WROTE partition table utilities in the 80's. You're right, it's trivial -- if you are a literate user who knows what a partition table is.

Most Windows users wouldn't know an MBR or partition table if it bit them on the ass.

And besides, these days, computers are using GUID partitioning. You gonna teach users how to use "parted"? Best of luck.

I'm not disagreeing that it's trivial in most cases. I'm saying that trivial or not it is impossible for today's average Windows user.

19 posted on 05/07/2015 7:25:20 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: dayglored

Mostly humor/gloming on../Windows works great for me... And has for 20+ years.


20 posted on 05/07/2015 7:25:43 PM PDT by loungitude (The truth hurts.)
[ Post Reply | Private Reply | To 8 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-62 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson