A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #1029  by EP_X0FF
 Fri May 07, 2010 5:15 pm
BTW, is there any solution to getting rid of this MBR Rootkit ?
fixmbr? :D Always worked in the past.
 #1035  by PX5
 Fri May 07, 2010 11:43 pm
No joy in VBox, No Joy in VM, All sorts of happiness in my live box, bazzas dug in too deep, blue screens were all I would see at first.

The newer batch seems far more revised, does a fine job of stealthing self and has sex with IE like linkoptimizer did.

Very Very impressed with this last release, runs cleanly inside the live enviroment but looks of code imply, youll never see it virtualized, probably the most impressive part of code.

Seems I had some links to dloaders somewhere around here, will see can I fetch em up. ;)