A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #11944  by R00tKit
 Sat Mar 03, 2012 12:54 pm
hi

http://translate.google.com/translate?h ... cblog.com/
Code: Select all
 Usual daily work systems on and off every day after work done at the server. The day after and the server reset had lost their boots. computers boot at first but after a few minutes have been reset and the other did not boot. 
I know of a similar situation that happened for a network, and seen one of their computer that its Partion Table was destroyed. Recovering data did not show anything.
Has anybody heard of such a virus?
Or have an idea how to find it?

thanks
 #11961  by EP_X0FF
 Mon Mar 05, 2012 1:17 am
Hello,

nobody can't tell anything about something that totally lacks any kind of description (name, sample, hash etc). This can be everything. Code for destroying partition table is quite simple.
 #12056  by __Genius__
 Sat Mar 10, 2012 8:33 pm
It uses the windows standard feature "diskpart" .
& as said it's quite simple to implement whether by handcoding or using microsoft's feature (simple VBS script)