2013-11-20

I do have a problem, how do I remove a persistent MBR malware? probably the malware hides itself in HDD sector that an OS couldn't even access. Already tried to format it and remove clean all partitions. And also tried to change OS type from windows to linux. Got infected from an office PC. Symtoms are whenever I'm online the mouse moves by itself probably a RAT type. Tried to analyze traffic but couldn't see any (e.g. somewhat like a Pushed Microsoft Security Update traffic).

Update:

My Malware Analyzation:

probably its much more beyond OS rootkits somewhat like BluePill (firmware rootkit) but not hardware dependent

it adapts on what OS you are using (injects and download over ethernet specific type of malware for different OS)

actively listens and sends outgoing connections (can't be blocked by firewall) on low-level

and also the fact that I know its a mbr malware is because, my office pc have a different type of board (logically it's not somewhat bios malware where it is hardware dependent and mostly this type of malware only attacks intel motherboards) using amd on my laptop

somewhat like a malware that was recently demo'ed at DEFCON (forgot the name of malware) but that is bios type of malware using openbios + seabios. It is fully undetectable so much low-level type of attack malware.

and on the malware that infects me seems like --- it embeds itself on removable flash disk on low level firmware so it could infect other systems.

Show more