PDA

View Full Version : [NEWS] Trojan.Mebratix.B – the Ghost in MBR


Chill-Out
03-05-2010, 16:31
Luned́ 03 Maggio 2010

http://www.symantec.com/content/en/us/about/images/photos/low_res/logos/symantec-logo-72dpi.jpg



Trojan.Mebratix infects the Master Boot Record (MBR) of a compromised computer. It is very harmful, advanced, and rare in the threat landscape. First appearing in March 2010, this version, also known as “Ghost Shadow” in China, copies the original MBR to the next sector and then replaces the original MBR with malicious code. As a result, Trojan.Mebratix will be loaded and then executed before the operating system, and it can’t be removed thoroughly by a normal reboot...............continua

Fonte: Symantec Security Response China (http://www.symantec.com/connect/pt-br/blogs/trojanmebratixb-ghost-mbr)