Free Republic
Browse · Search
General/Chat
Topics · Post Article

No word on how to protect from it or prevent it so far.
1 posted on 05/07/2015 7:01:37 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies ]


To: dayglored

Ping.


2 posted on 05/07/2015 7:02:09 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

It’s called Windows?


3 posted on 05/07/2015 7:02:13 PM PDT by nickcarraway
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

Can it overwrite the MBR on a Safe Boot / UFEI machine?


5 posted on 05/07/2015 7:08:41 PM PDT by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: All

More info:

Cisco researchers have identified a new malware sample, called Rombertik, that takes its detection evasion features one step further than the average cyber threat.

Instead of simply self-destructing when analysis tools are detected, Rombertik attempts to destroy the device’s master boot record (MBR), researchers wrote in a blog post.

This malware spreads through spam and phishing messages sent to possible victims.

In one example, attackers attempted to convince a user to download an attached document in an email. If downloaded and unzipped, a file that looks like a document thumbnail comes up. Although it mimics a PDF icon, it is actually a .SCR screensaver executable file containing the malware.

At this point Rombertik will first run anti-analysis checks to determine whether it is running within a sandbox. If it isn’t, it will then decrypt and install itself, which then allows it to launch a second copy of itself and to overwrite the second copy with the malware’s core functionality.

...

http://www.itnews.com.au/News/403620,new-malware-strain-destroys-master-boot-record-to-avoid-detection.aspx


7 posted on 05/07/2015 7:11:02 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Restoring a PC with its MBR deleted involves reinstalling Windows, which could mean important data is lost.

No, it doesn't.

10 posted on 05/07/2015 7:14:24 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

bing


14 posted on 05/07/2015 7:19:35 PM PDT by jetson (Can I catch you a delicious bass...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

No doubt created by liberal democrats so Hillary can say that is what happened to all of her e-mails. Yeah, that’s the ticket, virus destroyed my e-mails, and Morgan Fairchild’s too.


15 posted on 05/07/2015 7:20:21 PM PDT by TonyM
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Security expert Graham Cluley said destructive viruses such as Rombertik were quite rare.
So far.
18 posted on 05/07/2015 7:25:09 PM PDT by Bratch
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Self-destructing virus kills off PCs

Stop talking about Windows like that!

21 posted on 05/07/2015 7:29:38 PM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Destroying your computers runs completely counter to the purpose of watching your habits and stealing your personal data. This "article" is written like a junk e-mail ("destroys your computer!").

"involves reinstalling Windows, which could mean important data is lost"
This does not make logical sense, I've reinstalled Windows many times with no loss of data.

28 posted on 05/07/2015 7:41:22 PM PDT by Excuse_My_Bellicosity (Death before disco.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

This will continue until we bring back public hanging.


29 posted on 05/07/2015 7:44:19 PM PDT by SWAMPSNIPER (The Second Amendment, a Matter of Fact, Not A Matter of Opinion)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

Wont affect my awesome linux pc ha


33 posted on 05/07/2015 7:53:45 PM PDT by bicyclerepair (Ft. Lauderdale FL (zombie land). TERM LIMITS ... TERM LIMITS)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Restoring a PC with its MBR deleted involves reinstalling Windows, which could mean important data is lost.

Wrong. Restoring a corrupted MBR is child's play; I've done it several times for clients.

36 posted on 05/07/2015 8:01:28 PM PDT by Squawk 8888 (Will steal your comments & post them on Twitter)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

Whoever makes these things need to be drawn and quartered


46 posted on 05/07/2015 8:38:39 PM PDT by GeronL (Clearly Cruz 2016)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

I recommend capital punishment for the animals who create these things. A firing squad would be too kind.


51 posted on 05/07/2015 8:45:36 PM PDT by Steve_Seattle
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

A week ago my second desktop started acting weird, constantly restarting. I fixed the problem by hitting the F2 key and got into Windows. I then ran two anti-virus programs and it hasn’t recurred. Don’t know if this is related but I had never had that happen before. That was my wife’s computer and she is sure that she didn’t download anything but I’m guessing something was downloaded.


52 posted on 05/07/2015 9:33:28 PM PDT by RichardW
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Restoring a PC with its MBR deleted involves reinstalling Windows, which could mean important data is lost.

BS!

Boot into the recovery console:

bootrec /fixmbr bootrec /fixboot

And you're back. Granted, your system is still infected, but you're not in a boot loop.

I have to imagine they've figured out how to isolate and study this. Virtual machines are a wonderful thing.

53 posted on 05/08/2015 2:41:54 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

Sounds like Rombertik has been through some serious SERE training.       =;^)


58 posted on 05/08/2015 9:20:31 AM PDT by Bloody Sam Roberts ("It is never untimely to yank the rope of freedom's bell." - - Frank Capra)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson