{"id":33,"date":"2008-01-09T16:30:38","date_gmt":"2008-01-09T16:30:38","guid":{"rendered":"\/blogs\/news\/archive\/2008\/01\/09\/new-rootkit-hides-in-hard-drive-s-boot-record.aspx"},"modified":"2008-01-09T16:30:38","modified_gmt":"2008-01-09T16:30:38","slug":"new-rootkit-hides-in-hard-drive-s-boot-record","status":"publish","type":"post","link":"https:\/\/plexuk.co.uk\/?p=33","title":{"rendered":"New rootkit hides in hard drive&#039;s boot record"},"content":{"rendered":"<p><b>January 09, 2008 <\/b><a href=\"http:\/\/www.computerworld.com\">(Computerworld)<\/a> &#8212; A rootkit that hides from Windows on the hard drive&#8217;s boot sector is infecting PCs, security researchers said today. Once installed, the cloaking software is undetectable by most current antivirus programs.  <\/p>\n<p>The rootkit overwrites the hard drive&#8217;s master boot record (MBR), the first sector &#8212; sector 0 &#8212; where code is stored to bootstrap the operating system after the computer&#8217;s BIOS does its start-up checks. Because it hides on the MBR, the rootkit is effectively invisible to the operating system and security software installed on that operating system.  <\/p>\n<p>&#8220;A traditional rootkit installs as a driver, just as when you install any hardware or software,&#8221; said <a href=\"http:\/\/www.computerworld.com\/action\/inform.do?command=search&#038;searchTerms=Oliver+Friedrichs\">Oliver Friedrichs<\/a>, director of <a href=\"http:\/\/www.computerworld.com\/action\/inform.do?command=search&#038;searchTerms=Symantec+Corporation\">Symantec Corp.<\/a>&#8216;s security response team. &#8220;Those drivers are loaded at or after the boot process. But this new rootkit installs itself before the operating system loads. It starts executing before the main operating system has a chance to execute.&#8221; Control the MBR, Friedrichs continued, and you control the operating system, and thus the computer.  <\/p>\n<p><a title=\"http:\/\/www.computerworld.com\/action\/article.do?command=viewArticleBasic&#038;articleId=9056378&#038;source=rss_news10\" href=\"http:\/\/www.computerworld.com\/action\/article.do?command=viewArticleBasic&#038;articleId=9056378&#038;source=rss_news10\">http:\/\/www.computerworld.com\/action\/article.do?command=viewArticleBasic&#038;articleId=9056378&#038;source=rss_news10<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>January 09, 2008 (Computerworld) &#8212; A rootkit that hides from Windows on the hard drive&#8217;s boot sector is infecting PCs, security researchers said today. Once installed, the cloaking software is undetectable by most current antivirus programs. The rootkit overwrites the hard drive&#8217;s master boot record (MBR), the first sector &#8212; sector 0 &#8212; where code [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[338],"class_list":["post-33","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-uncategorized"],"_links":{"self":[{"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/33","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=33"}],"version-history":[{"count":0,"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/33\/revisions"}],"wp:attachment":[{"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=33"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=33"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plexuk.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=33"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}