Revealing a new variant of computer virus can destroy itself when detected
The latest virus variant has been discovered by researchers from Cisco security firm to be able to self-destruct to avoid being "caught up" after virus analysis applications discover them.
Download Bkav Pro Internet Security
According to security researchers at Cisco, a new type of malware called Rombertik has been discovered that can destroy itself important data stored in Windows system files on the Master Boot Record ( A key component of the hard drive and a storage partition for disk information ), causing the machine to reboot several times to escape detection of virus and malware analysis tools. At the same time, when the Master Boot Record fails, it will make it harder to recover data on the hard drive than ever before.
The Master Boot Record starts with the executable code before the operating system is booted. When the Master Boot Record is overwritten by Rombertik, it will display the " Carbon crack attempt, failed " command and then put the user in an infinite loop to prevent the system from continuing to boot properly.
No matter how many times the user restarts, the screen will still display the text until the computer is reinstalled.
This new type of malware can also trick researchers' sandbox tools by writing a random data byte and moving it to system memory more than 960 million times. continuity.
Security expert Graham Cluley said the type of self-destruct software like Rombertik is quite rare because today's malware never wants to get noticed because its main goal is to silently "steal" information. precious information of users for a long time.
Cisco-defined Rombertik may appear a lot through spam and phishing messages sent to victims, enticing users to download and extract malicious attachments.
Once installed and spread on the user's computer, Rombertik malware will steal the user's login and personal data when accessing any website before sending this data to the attacker.
You should read it
- What is the Master Boot Code?
- What is the Master Partition Table?
- Instructions for creating USB Multiboot start multiple operating systems
- 7 Cisco security tips
- 10 commands to master when working with Cisco IOS
- How to install dual boot Windows 10 and Windows Server
- What is a Volume Boot Record (VBR)?
- The new worm 'slips' Microsoft's WGA software
May be interested
- Destroy the autorun virus in USB or on PC with 4 simple waysbecause windows will perform these autorun.inf files first, some hackers take advantage of this to install the virus into the autorun file so that it can spread the virus easily to the entire system. this article will show you how to remove autorun virus from usb or pc.
- Warning: Bkav detected more than 700,000 computers in Vietnam infected with virtual money digging virus that slowed down the computerbkav has just warned that more than 735,000 computers in vietnam have been infected with w32.coinminer virus. this is a dangerous virtual money digging virus, it will take control and take advantage of the victim's computer to dig virtual money.
- What is idp.generic?what is idp.generic ?. have you ever run an anti-virus program or played a game on a windows computer and suddenly received a warning that detected a threat called idp.generic? the good news is that this positive case can only be misdiagnosed. however, there is a possibility that your computer is infected with trojan virus.
- This is the person who created the world's first computer virusno one would have imagined that one of the dangers of today's it world - computer viruses - was born out of a mischievous joke of a 9th grade student.
- Virus warning to destroy Sector 0 hard drive is lostinformation about a virus that permanently destroys hard drives is a rumor that has been spreading since 2000. this is just a rumor (hoax), but there is no such virus in practice.
- Many 'victims' have not been able to kill YM virus properlyalthough the hanoi university of technology bkis network security center insists on updating 9 'made in vietnam' worms into the latest bkav version, many people still cannot destroy them. the reason is that the procedure & quitting has not been done properly
- New variant Gozi Trojan raged againsince april 17, there have been more than 2,000 home users falling victim to the latest variant of gozi data theft trojan. the new gozi variant has been rated extremely dangerous with new upgrades and equipped with the ability to hide itself more highly in the face of.
- Viruses impersonating Microsoft delete databkav's virus surveillance system, which has detected many search results, has led to a tool to impersonate microsoft software firms. this tool is a virus that destroys data, it will erase all data on the c drive when activated.
- New malware appeared to take advantage of COVID-19 to wipe out the computer and overwrite the MBRwhile the corona virus is raging all over the world, some hackers have quickly developed malware to destroy infected systems by wiping everything out, or writing on the master boot record (mbr) of the machine. count.
- Keep your computer safe when attaching USBone of the most dangerous and popular viruses on usb is the autorun virus and the hidden virus folder. with the autorun virus, every time you double-click the usb drive icon in my computer, the virus will immediately spread to the computer, causing many system errors.