Friday, January 04, 2008

Vista and XP - Rootkit exploit in the wild

This rootkit is using the MBR flaw. The MBR can be written to from within Windows. The rootkit installs itself ( 244K ) on the last sectors of the users disk and then modifies other sectors including sector 0. The code is run before your PC boots up into XP, Vista or NT and has full control of the boot process which means it can install and run any application it wants without you, XP, Vista or NT knowing about it.

Read the article HERE.


