Author Topic: Does avast protect us from MBR rootkit infection?  (Read 3312 times)

0 Members and 2 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Does avast protect us from MBR rootkit infection?
« on: March 06, 2008, 09:24:13 PM »
Hi malware fighters,

MBR rootkit was found for the very first time late last year. It is nearly impossible for normal anti-malware software to remove it. Furthermore it is actively spread through the Internet.
This malware infects the Master Boot Record of the hard disk, and can infect the operational system
before it has been loaded.
To see whether a system has been infected the security software must be run before the rootkit.

Most known virus- and rootkitscanners load after the operational system has started. so they
have already lost the battle against this kind of malware, as is admitted by F-Secure very openly here:

http://www.f-secure.com/weblog/archives/00001393.html

In the case of MBR rootkit a program like Blacklight can only guess the system has been infected.
Certainty can only bring the use of a boot-CD.

One thing is sure this malware has been created by professional miscreants,
and during the first two attacks of MBR rootkit this malware made over 5000 victims.
The rootkit downloads other additional malware, for instance malware to plunder bank-accounts.
It is spread through drive-by-downloads to abuse leaks and vulnerabilities
in both several Microsoft programs and AOL and Yahoo software.
That this means a serious threat is obvious because the proof of concept for two of
these exploits are just over one month old.

My question here is are users of avast protected against these drive-by-downloads? Second is
how to best protect against this malware, because when you have it on your hard disk
you are really in between a rock and a hard stone, I think,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Does avast protect us from MBR rootkit infection?
« Reply #1 on: March 06, 2008, 09:38:52 PM »
Hi polonus.

I think avast can detect it. There is a thread about it here

http://forum.avast.com/index.php?topic=32559.0

this bug supports my theory that the Rc should be installed by default. I think also on a home/private use machine, the registry should be edited so no password is needed. Sometimes it won't  recognize the password.

Just my thoughts on it. I know the password is there for security reasons.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Does avast protect us from MBR rootkit infection?
« Reply #2 on: March 06, 2008, 11:32:09 PM »
I wonder if this would be a candidate for the avast anti-rootkit in the boot-time scan if you haven't managed to avoid its download and installation.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security