Stoned Bootkit - PowerPoint PPT Presentation

1 / 6
About This Presentation
Title:

Stoned Bootkit

Description:

These methods allows infector.exe to infect the MBR from Windows ... Not disclosed by the developer however ... Boot using a bootable antivirus occasionally ... – PowerPoint PPT presentation

Number of Views:75
Avg rating:3.0/5.0
Slides: 7
Provided by: abc7104
Category:

less

Transcript and Presenter's Notes

Title: Stoned Bootkit


1
Stoned Bootkit
2
Stoned Bootkit
  • How it infects
  • Uses the following Windows function (usually C)
  • CreateFile()
  • WriteFile()
  • These methods allows infector.exe to infect the
    MBR from Windows
  • Stoned bootkit itself infects different sectors
    of the hard disk

3
Stoned Bootkit
  • Prevention
  • There are alternatives to prevent the
    installation of bootkit
  • Not disclosed by the developer however
  • But that undisclosed method will not work on
    upcoming Stoned Bootkit v3
  • Hence, the best prevention method is to
    write-protect sector 0
  • This can be configured in BIOS
  • Needs to revert settings whenever OS needs to be
    updated or reinstalled

4
Stoned Bootkit
  • Detection
  • Always have the latest updated Antivirus running
    real time
  • Boot using a bootable antivirus occasionally
  • This checks for boot sector viruses undetected at
    Windows level

5
Stoned Bootkit
  • If infected
  • Use Windows Recovery Console CD to reinstall MBR
  • Then run fixmbr
  • Reinstalling the MBR does not affect the OS

6
Stoned Bootkits
  • Miscellaneous
  • MBR alone cannot be encrypted, only the hard disk
    as a whole
  • Hard disk encryption does not prevent
    installation of Stoned bootkit
  • Primary purpose of encryption is to only secure
    files, doesnt prevent viruses
Write a Comment
User Comments (0)
About PowerShow.com