"Ransomware" Infecting Master Boot Record & Preventing The OS From Loading
Security experts at Trend Micro has find out ransomware which blocks systems from booting. A typical ransomware encrypts files or restricts user access to the infected system. However, it has been found that this particular variant infects the Master Boot Record (MBR), preventing the operating system from loading. Based on analysis, this malware copies the original MBR and overwrites it with its own malicious code. Right after performing this routine, it automatically restarts the system for the infection take effect. Users can, however, save themselves 920 hryvnia by following the experts' instructions for removing the infection. This essentially consists of running the recovery console from the Windows Installation DVD and restoring the original MBR using the fixmbr command.
Last February, certain attackers compromised the website of the French confectionery shop Ladurée to spread this malware. Users who visited the said site when it was compromised ended up with systems infected with TROJ_RANSOM.BOV. This variant was found to display a notification that impersonates the French National Gendarmerie and demands payment from affected users. The people behind this attack have also impersonated police notifications from Italy, Germany, Belgium, and Spain.
LINK TO OUR HOME PAGE :


Categories:
NEWS
,
security-news
,
vulnerablity