This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

First (well, second) BIOS rootkit in the wild!

1 min read

This thread's last reply is from September 14, 2011, 11:49 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Researchers have discovered one of the first pieces of malware ever used in the wild that modifies the software on the motherboard of infected computers to ensure the infection can't be easily eradicated.

Known as Trojan.Mebromi, the rootkit reflashes the BIOS of computers it attacks to add malicious instructions that are executed early in a computer's boot-up sequence. The instructions, in turn, alter a computer's MBR, or master boot record, another system component that gets executed prior to the loading of the operating system of an infected machine. By corrupting the processes that run immediately after a PC starts, the malware stands a better chance of surviving attempts by antivirus programs to remove it.


Full Story @ The Register
Analysis @ Webroot
ZB