Home Malware Programs Viruses Virus.Boot-Stonedbootkit

Virus.Boot-Stonedbootkit

Posted: May 16, 2011

Virus.Boot-Stonedbootkit is a boot virus that can damage master boot record or MBR (master boot record) code of the targeted computer system. Virus.Boot-Stonedbootkit includes the rootkit-specific tactics generated to conceal the software existence on the computer system. Virus.Boot-Stonedbootkit may hook functionality in Windows system files to enable a remote attacker run applications with administrative privileges. Boot.Stonedbootkit will alter the master boot record code and install a functionality in system files that may enable the hacker to obtain control of your computer. Virus.Boot-Stonedbootkit should be removed from an infected system upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Stoned\Applications\Forensic Lockdown Software.sys
    2 c:\Stoned\Applications\Hibernation File Attack.sys
    3 c:\Stoned\Applications\Sinowal Loader.sys
    4 c:\Stoned\Applications\Windows.sys
    5 c:\Stoned\Drivers\Black Hat Europe 2007 Vipin Kumar POC.sys
    6 c:\Stoned\Drivers\Sinowal Extractor.sys
    7 c:\Stoned\Drivers\Sinowal.sys
    8 c:\Stoned\Master Boot Record.bak
Loading...