Galdorf
Well-Known Member
- Reaction score
- 502
- Location
- Ontario, Canada
Wow this thing is in the wild have a customer that has it, i have tried everything to remove this thing it prevents bios flashing and boot block writes.
Even if you manage to boot off the OS cd and go into the command prompt and do a fixmbr does not work, all av's on a bart cd can't remove it, even tdsskiller cannot remove this thing.
Slaving the hd is no use if you clean boot block put it back in original machine as soon as bios rootkit kicks in an re-writes the rootkit boot block short of replacing the motherboard there does not seem anything i can do, unless i can find a eeprom flasher and flash bios manually.
Even if you manage to boot off the OS cd and go into the command prompt and do a fixmbr does not work, all av's on a bart cd can't remove it, even tdsskiller cannot remove this thing.
Slaving the hd is no use if you clean boot block put it back in original machine as soon as bios rootkit kicks in an re-writes the rootkit boot block short of replacing the motherboard there does not seem anything i can do, unless i can find a eeprom flasher and flash bios manually.