MSFN Forum: Microsoft clarifies MBR rootkit removal advice

Jump to content






Icon Latest News Comments


Icon MSFN Statistics

  • Total Posts 802610
  • Total Members 102348
  • Newest Member xor 
  • Online At Once Record 17869
  • Online Now: 2684



    Icon Recommended Sites

    AskVG.com Bink Filehorse FreewareFiles IT Magazine lunarsoft Where unprofessional journalism looks better OSNN TechLog The Windows Club WinBeta

Microsoft clarifies MBR rootkit removal advice -----

Posted on Jun 30 2011 05:41 PM by xper  in Security | Viewed 2825 Times

Microsoft yesterday clarified the advice it gave users whose Windows PCs are infected with a new, sophisticated rootkit that buries itself on the hard drive's boot sector. Several security researchers agreed with Microsoft's revisions, but a noted botnet expert doubted that the advice guaranteed a clean PC.

Last week, the Microsoft Malware Protection Center (MMPC) highlighted a new Trojan, dubbed "Popureb," and said that the only way to eradicate the malware was to use a recovery disc.

Because a recovery disc returns Windows to its factory settings, Microsoft was essentially telling users that they needed to reinstall Windows to completely clean an infected PC.

That recommendation was similar to what Microsoft had offered more than a year ago, when another Trojan buried rootkit code into the master boot record (MBR) of the PC's hard drive.

On Wednesday, MMPC engineer Chun Feng clarified Microsoft's advice.

"If your system is infected with Trojan:Win32/Popureb.E, we advise fixing the MBR using the Windows Recovery Console to return the MBR to a clean state," Feng wrote on an updated blog yesterday.

Feng provided links to instructions on how to use the Recovery Console for Windows XP, Vista and Windows 7.

Once the MBR has been scrubbed, users can run antivirus software to scan the PC for additional malware for removal, Feng added.

More @ NetworkWorld




0 Comments

Page 1 of 1

No comments have been made yet

You do not have permission to leave comments on this article
Page 1 of 1



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy