A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #973  by Alex
 Sun May 02, 2010 2:45 pm
Thanks for interesting sample :)

Alex
 #974  by Elite
 Sun May 02, 2010 7:35 pm
Very interesting sample.

Very amused to see another MBR rootkit. We'll see if this becomes the next TDL3+ or Mebroot.
 #975  by Elite
 Sun May 02, 2010 7:46 pm
Either sample appears to not be functioning under VirtualBox, or it is completely invisible.

Anyone tried it on VMWare/real machine?

I need to verify the MBR of this VM.
 #976  by EP_X0FF
 Mon May 03, 2010 2:15 am
Hi,

I've tried it on VPC and it killed MBR.

Regards.
 #978  by Avinash
 Mon May 03, 2010 3:22 pm
Hi Respected Members,

I am very much new here. BTW i am a respected member of Wilders. Today i heard about this Rootkit, so i came here to test it.

BTW can anybody tell me is this Rootkit VM aware or not? Secondly i have saw moderator's post that it managed to kill MBR but whose MBR it managed to kill, VM Machine's or Host Machine? Is it possible to infect Host Machine MBR by running this under VM Machine?

Warm Regards
Avinash

Blog:- http://technonxt.wordpress.com
 #979  by EP_X0FF
 Mon May 03, 2010 4:17 pm
Hello and welcome,
Avinash wrote:Secondly i have saw moderator's post that it managed to kill MBR but whose MBR it managed to kill, VM Machine's or Host Machine? Is it possible to infect Host Machine MBR by running this under VM Machine?
1. VM Machine.
2. No.

Regards.
 #980  by Buster_BSA
 Mon May 03, 2010 4:28 pm
Just to make more extensive the answer.

No malware running under a virtual machine (vmware, virtual pc, virtualbox, ...) can write to host if it´s not through a specific exploit for that virtual machine or through a feature like "shared folders" from vmware.
 #982  by Alex
 Tue May 04, 2010 12:44 pm
Tested on VmWare 6.5 with Windows XP SP2. After rebooting I don't see any of infection symptoms (there is nothing suspicious injected into explorer.exe process), GMER and Radix says that MBR is clean, only RootRepeal 1.3.5 shows sth like this:
Image

It is rather a false positive generated by RR. I've ran RR on clean Windows XP and it showed same results...

Alex
Last edited by Alex on Tue May 04, 2010 12:49 pm, edited 1 time in total. Reason: false positive