MBR Rooted

Discussion in 'malware problems & news' started by Cretemonster, Jan 2, 2008.

Thread Status:
Not open for further replies.
  1. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    ~removed virus total result....Bubba~
    Lool. Just watch your ethernet leds and unplug if too suspicious... lool, last chance.

    @cretemonster: Do you still have this HTM? But could also be false alarm.
     
    Last edited by a moderator: Feb 4, 2008
  2. Cretemonster

    Cretemonster Registered Member

    Joined:
    Mar 31, 2005
    Posts:
    79
    Think Ill trust what I can see better than what someone else sees. ;)
     
  3. Montpellier

    Montpellier Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    20
    Looks like the new version is out:
    http://www.prevx.com/freescan.asp
     
  4. Cretemonster

    Cretemonster Registered Member

    Joined:
    Mar 31, 2005
    Posts:
    79
  5. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    They split the traffic, looks beasty.
     
  6. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    The infection of MBR is their way of survival. They can be spambots, PSW trojans, RATs, DDoS tools, ad-clickers, etc
     
  7. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Exactly.
     
  8. controler

    controler Guest

    So what's the big deal this is all old hat with a rootkit twist.
     
  9. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    I would like to see the client of the hackers that control MBR, do they use console or Gui to control their little Matrix. Probably either nice Gui like Shark.
     
  10. Cretemonster

    Cretemonster Registered Member

    Joined:
    Mar 31, 2005
    Posts:
    79
    Reckon this bugger will wander over to the host?

    Symantec is blogging again.
     
  11. Cretemonster

    Cretemonster Registered Member

    Joined:
    Mar 31, 2005
    Posts:
    79
    Nothing to host yet but folks best be updating,seems dw is the only one to find and remove the new addition so far but others are just recieving samples as we speak.

    A big thanks to Alexey and PG for the excellent information and keen eye on the only way to really tell if its there,will allways be that unknown traffic and if your up on domain names and such,this will toss a red flag quick.

    I will say this,they are using an odd form of HWD Acceleration not seen by me before,this is where I get lost in virtualization. :gack:
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    @Cretemonster

    Whats your take on this latest intruder and how it will fair with the likes of SandboxIE specifically speaking? Or HIPS like ssm or eqs.

    Thanks
     
  13. Cretemonster

    Cretemonster Registered Member

    Joined:
    Mar 31, 2005
    Posts:
    79
    This one is a little more interesting,I had a chance to get more personal with it allready.

    It will honestly depend on how well the system activity is monitored,everything that happens in that "Less than a minute" portal is totally malicious and quite obvious,Id be happy to test what I can today but im running outa machines and IPs to work with. :doubt:

    Cheers to Gmer,update in progress,

    Cheers to Marco and his gang as well the folks at DrWeb.

    Since Symantec did the write up,cheers for that too but Ill never install your 20 Ton app onto 2 ton machine again....I have had roots that were easier to rip out! ;)
     
  14. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Seems so and side effects like downloader junk. Type III Malware.

    HWD sounds like handle window :D :D :D
     
  15. fcukdat

    fcukdat Registered Member

    Joined:
    Feb 20, 2005
    Posts:
    569
    Location:
    England,UK
    Hey thanks for the pointer.Some the original urls are still dispencing the MAT.. file:)
     
  16. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Did you know why they call it mat?
    I guess because of this russian mat slang.
     
  17. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,226
    Hello,
    mat files are Matlab files.
    Mrk
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.